Re: Local Admins

From: Torgeir Bakken (MVP) (Torgeir.Bakken-spam_at_hydro.com)
Date: 11/11/03


Date: Tue, 11 Nov 2003 22:02:34 +0100

Mr. Fixit wrote:

> Management has decided to make all Authenticated Domain users Local Administrators on their office desktop running Win2k and WinXP. Please help me provide information on why this should not be done.
> Any response will be appreciated.

Hi

You could consider using the builtin "NT Authority\Interactive" instead, meaning
everybody logged in interactively (through the console) on the computer.

We add NT Authority\Interactive in the local Administrators group to let all
domain users automatically be local admins when they log on to a computer
interactively (thus avoiding the issue with cross network admin rights that
"Authenticated Domain users ", "Domain Users" or
"NT AUTHORITY\Authenticated Users" will give you).

--
torgeir
Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: http://www.microsoft.com/technet/scriptcenter


Relevant Pages

  • Re: Local Admins
    ... We add NT Authority\Interactive in the local Administrators group to let all ... domain users automatically be local admins when they log on to a computer ... Microsoft MVP Scripting and WMI, ...
    (microsoft.public.security)
  • Re: Authenticated Users
    ... local Administrators group to let all domain users automatically be local admins when they log on to a computer interactively. ... "Domain Users", "NT AUTHORITY\Authenticated Users" or any other global security group because you avoid the issue with cross network admin rights that these groups introduces. ... torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
    (microsoft.public.windows.server.scripting)
  • Re: Script to enumerating list of Local Admingroup member of all d
    ... How to Configure a Global Group to Be a Member of the Administrators Group on ... This is more secure than adding "Authenticated Domain users", ... avoid the issue with cross network admin rights ... torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
    (microsoft.public.windows.server.scripting)
  • Script (s) to help with file security audit
    ... I need to do a few things as part of our file security audit (we will be ... to return the path and file name as separate items rather than one long ... - Get a list of all domain users along with their AD location. ... I do have some limited experience with scripting and have already scripted ...
    (microsoft.public.scripting.vbscript)
  • Re: local admin one each local machine..
    ... > local admin on each machine.. ... We add "NT Authority\Interactive" in the local Administrators group ... This is more secure than adding "Authenticated Domain users ", ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windows.group_policy)

Quantcast