Re: logon/power-users group question

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/10/05


Date: Wed, 9 Mar 2005 22:28:55 -0600

Power users by default can do a lot to a computer and have write permissions
to program file and system files folders though you can modify that. Power
users can also create shares if file and print sharing is enabled. Power
users can also create local accounts which means that they could possibly
create a local user account, put it in the power users group, and then logon
to the computer with that account to bypass domain Group Policy for users.
You could try to configure the user right on those domain computers to
include only domain users and administrators which could prevent that.

You can limit logon to domain computers in a couple of ways. In a users
account in AD Users and Computers you can specify which domain computers a
user can logon to. Also you can use the user rights logon locally and deny
logon locally to control who can logon to a domain computer. This can be
done at the local computer level or at the domain or Organizational Unit
level with Group Policy. Be careful with deny user rights as they override
allow user rights and remember that administrators are also members of the
users and everyone groups. The security guide from Microsoft call Threats
and Countermeasures has much more detailed info and can be found at the link
below. --- Steve

http://www.microsoft.com/technet/security/topics/serversecurity/tcg/tcgch00.mspx

"Altria" <urbantec92@msn.com> wrote in message
news:%23ktajwNJFHA.2852@TK2MSFTNGP09.phx.gbl...
> Hello All,
> By default, are users of a domain allowed to logon to any workstation
> within the domain?
> If so, how can I limit specific users to only be able to logon to specific
> workstations?
> Also, if users are able to login to any machine with a valid user account
> how does this effect the security on the machine. For example, if group
> policies are applied to specific users and machines based on OU then what
> happens to a user who is not in that OU but in the domain and is able to
> logon to the workstation?
> Finally, a little off-topic, if I set my users to have power-user rights
> via configuring Network ID are they not suppose to be able to install
> programs and other misc things(eg. wallpaper)? I thought that this group
> essentially can install programs but not modify any system files (eg. OS
> dependent files). Does this also include not being able to write into
> %systemroot% or modifying registry during program installations?
> TIA,
> Altria
> BTW, Win2k3/2k and XP pro clients
>



Relevant Pages

  • Re: logon/power-users group question
    ... users to the power users group (via My computer>Properties>Computer ... and then logon to the computer with that account to bypass domain ... > You can limit logon to domain computers in a couple of ways. ...
    (microsoft.public.windows.server.security)
  • Re: logon/power-users group question
    ... There is no power users at the domain level - it exists only on the computer ... > local users on the assigned workstations. ... >> means that they could possibly create a local user account, ... >> You can limit logon to domain computers in a couple of ways. ...
    (microsoft.public.windows.server.security)
  • Re: Interactive logon
    ... If you were to go to the local policy and modify to ... way prevent logon remotely then the user could attach locally and modify the ... My point is once a user is a local admin you really can't stop them from ... Is there a way to set the permissions so this account will ...
    (microsoft.public.windows.server.active_directory)
  • [EC-SA-01.2003] Windows XP "welcome screen" exposes the names of all the members of the l
    ... logon screen with what is called "Welcome Screen". ... (including the original administrator account, ... Using the "welcome screen" actually disables / ignores the security ...
    (Bugtraq)
  • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
    ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
    (microsoft.public.windows.server.sbs)

Loading