Re: Computer Management Security Question

From: Danny Sanders (Danny.Sanders_at_cpcNOmedSPAM.org)
Date: 07/27/04


Date: Tue, 27 Jul 2004 14:29:23 -0600

Sounds like you made your users domain admins instead of admin of their
local computer.
If so take them out of the domain admin group and, from their local computer
add their domain account to the local admin group.
They will be able to install, update, their local computer but no control
over the domain controllers.

hth
DDS W 2k MVP MCSE

"Dave W." <DaveW@discussions.microsoft.com> wrote in message
news:4CF603E6-B7BF-4382-8080-E6CF7C9AD2D6@microsoft.com...
> We use a Windows 2003 DC and have found that all of our users can choose
the "Manage" on "My Computer" and then choose the domain controller PC as
the PC to manage. They can then add shares, shut down services, etc. which
defeats all the security.
>
> How can I prevent users from specifying another computer name in the
computer management console snap-in and/or how do I restrict a computer from
allowing on specific users to connect.
>
> Note that all of our users are administrators which I know is bad, but
they are software developers and need to constantly re-install, update
registries, etc.
>
>



Relevant Pages

  • One more thing : full sharing between domain admins
    ... But what about logging on to local computer. ... account but other domain admins could still see my ... > mentions a determined domain administrator ultimately has ways to gain ...
    (microsoft.public.win2000.security)
  • Re: Cannot Browse to Certain PCs
    ... "Marcin" wrote ... group on the local computer. ... While Domain Admins global group is ... automatically added to local Administrators when the computer joins the ...
    (microsoft.public.windows.server.general)
  • User permission problem
    ... I have a single forest single domain Windows Server 2003 AD environment. ... have several techs that join computers to the domain, install software, etc. ... I have a GPO in place that adds a security group to the local XP admin group ... Putting them in the domain admins group eliminates the problem. ...
    (microsoft.public.windows.server.general)
  • Unable to open default email folder . Exchange 2003 , Outlook 2003
    ... I had one user on Tuesday that was trying to connect to the Exchange server ... I log in as him and I then tick and untick on Work Offline so Outlook can ... If i remove them from the admin group it doesnt work. ... If this continues then i will have to make all our users Domain Admins ...
    (microsoft.public.exchange.admin)
  • Re: Domain Admins removed from local admin group
    ... "restricted grups. ... Even if the user is local admin and removes the domain admins ... admin group. ...
    (microsoft.public.windows.server.general)

Quantcast