Re: Should a user be able to unjoin from domain?



sysadmin guy wrote:
I have a user, who does have local admin and has managed to unjoin
his laptop from the domain and put into his own workgroup. Should he
have been able to unjoin from the domain without knowing a user name
and password for someone with domain admin security group membership?

Of course he can. Local Admin rights mean that they own the machine that
they have those rights for, and can do whatever they like with it. He
hasn't modified the domain by joining his workstation to its own workgroup
instead of your domain, so rights on the domain are not relevant here.

This is just one of the reasons many people advise you not to give admin
rights to end users.

--
--
Rob Moir, Microsoft MVP for Security
Blog Site - http://www.robertmoir.com
Virtual PC 2004 FAQ -
http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html
I'm always surprised at "professionals" who STILL have to be asked:
"Have you checked (event viewer / syslog)".


.



Relevant Pages

  • Re: Access Security not secure
    ... I created the Administrator and added him to the admin ... database, removed all the rights from the user group. ... access2000 or access2002 that has the default workgroup. ...
    (microsoft.public.access.security)
  • Re: Access Security not secure
    ... new workgroup when I secure it with the wizard all seems ... to work well until I try to access the database on the ... >> I created the Administrator and added him to the admin ... removed all the rights from the user group. ...
    (microsoft.public.access.security)
  • Unable to connect to workgroup
    ... I am logged in as the admin and am getting a message that I don't have rights ... to connect to the workgroup. ... I can ping the other machine and have internet access. ...
    (microsoft.public.windows.mediacenter)
  • Re: Should I still buy SBS 2003 Premium w/ ISA in light of XP SP2s ICF2?
    ... Admin rights is a very simple story. ... relying upon the firewall to block accordingly the access to workstations, ... don't have the same level of packet-filtering in your favor that ISA ...
    (microsoft.public.windows.server.sbs)
  • RE: Impact of removing administrative rights in an enterprise running XP
    ... While it is true that you can push out patches and software via group ... reporting mechanisms for software/patch installations whatsoever. ... Quite often, the admin rights are ...
    (Focus-Microsoft)