Re: prevent application installations by power users



In news:595C9DA8-A6D6-40F4-8394-571EF070A6B9@xxxxxxxxxxxxx,
jinu <jinu@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
Hello,

Our domain users are locally power users.

Why?

Is there any way to block these users from installing applications.

They will be able to install some applications. Local Power Users are nearly
Administrators.

At GPO, told not to run regedit.exe

That wouldn't make any difference. You can do a lot of things via group
policy, but the best way to deal with this is to take away the permissions
so they're just Users. If you have software running on those PCs that won't
run right otherwise, see if you can change the permissions in the file
system & registry sufficiently so that ordinary users can write to those
areas as they need to. FileMon and RegMon may help you out here.

Regmon:
http://www.microsoft.com/technet/sysinternals/utilities/Regmon.mspx

Filemon:
http://www.microsoft.com/technet/sysinternals/utilities/filemon.mspx

OR Process Monitor
http://www.microsoft.com/technet/sysinternals/utilities/processmonitor.mspx

Regardless of what rights you give them, you should probably put together a
written Acceptable Computer Use policy that everyone has to sign.


But still now luck.

Please help.



.



Relevant Pages

  • Re: Restricted Groups and Power Users
    ... I have also created a policy to control the Power Users group to avoid this ... over the machine local Administrators group of computers ... That GPO is not affecting the ...
    (microsoft.public.windows.group_policy)
  • Re: Remove permissions to install software from Power Users group
    ... There are some exploits that allow power users to elevate to administrators. ... This will allow you to relax permissions on particular registry keys and files so that these apps will run under standard user accounts. ... > the Power Users group? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: User Profile Question
    ... This is likely because of filesystem permissions on their machines, ... Some of these users are Administrators of their own computer. ... After changed the local user rights from Administrator to Power Users the ... No group policy or domain policy are active.... ...
    (microsoft.public.windows.server.security)
  • Re: Prevent Power users from modifying Local SAM
    ... You can't recreate those groups exactly [not even close to administrators] ... foolproof way to not allow power users to be able to create user accounts as ... it is hard coded into the operating system and not a user right/privilege. ... permissions as power users and then in Local Security Policy give users the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Event ID: 1202
    ... I could not find Power Users in these policy files. ... SeEnableDelegationPrivilege = Administrators ... SeRestorePrivilege = Backup ...
    (microsoft.public.win2000.active_directory)