Re: Locking Down workstation



Hi

Presumably you know how to set up Group Policies to run from your
server. There's lots of info out there, including the article at
http://www.windowsecurity.com/articles/Windows-XP-Group-Policy-Windows-2000-Domain-Part1.html

Local Admin or even Power User access is dangerous in the wrong hands -
as you've discovered... and as I've also discovered!

I've never fiddled with running gpedit.msc to permit users to add
printers but it should work. The policies give you quite a bit of
control

Good luck however. Once users have full control of their computer they
are reluctant to give it up.

Peter



nesdog wrote:
Hi,

I've got 75 users with laptops that log onto our domain. They have always
been given local Admin rights. Now we want to lock them down, but still allow
them to install local printers, or config home wireless. But nothing else!
(including adding browsers, apps, etc! )

Will the local Users group give them this access? When I tested it, it
appeared that only Add Network Printer was available, not the local one.
Power User seemed to get the same settings.

We had one of these machines infect our network courtesy of a user who had
too much Admin rights so any help would be appreciated.

Thanks,

Sheldon

.



Relevant Pages

  • Re: Delegating Permissions
    ... You can not safely delegate permissions to modify a DC without giving enough rights for the delegate to escalate themselves to administrator, domain administrator, and eventually Enterprise Admin. ... Add/remove printers on DC ... We do not want local admin to have the right to backup up/restore files or manage or add printers on DC's outside of their division ...
    (microsoft.public.windows.server.active_directory)
  • Re: how to forbid users to connect directly to printers
    ... they have already been granted local admin rights, ... but that doesn't really explain why you you can't *revoke* the rights. ... Perhaps this is a silly suggestion, but if you don't give users ... (can't add local printers or printer ports at all). ...
    (microsoft.public.windows.server.general)
  • Re: User cant browse network printers
    ... Is the user a local admin? ... He could browse printers before. ... folder where his My Documents folders reside. ... Offline files: ...
    (microsoft.public.windows.server.sbs)
  • Re: User accounts being deleted
    ... > doesn't run correctly unless the user has local admin ... >>Hi Andy, ... >>Why would a user need local admin rights? ... >>group policies for this, then there must be someone else ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: Password Policy
    ... In win2k / active directory you can use group policies to rename and/or ... Then whenever the group policy is set to propagate the local admin info ... Subject: Password Policy ... handle it for workstations? ...
    (Security-Basics)

Loading