Re: Domain Users are able to install applications.



Wobzo <Wobzo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
I have a network where the newly deplouyed Workstations were tested
such that Domain Users were unable to install anything.
However it has recently happened that one of the so said users
installed GE (Google earth).
I found this to be very concerning as this should not have been
possible. approximately 6+ months ago, I personally tested the
ability to install GE as a user and it was not possible.
They also seemed to be able to install "MySpaceIM". My initial
thought was how was the user able to enter the keys under
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall".
I think this maybe launching the application under "SYSTEM"
credentials.
All other local accounts are disabled and users are not members of
anything other than local users group.
What else are people able to run under the "SYSTEM" account?
How can I prevent the users from installing?

To add to the other reply -

You can't prevent limited users from installing software entirely, merely
based on their local group membership. As you've just seen, a lot of apps
don't require special permissions to install ...they don't write to the
restricted areas of the registry & file system.

You should look into group policy options to lock down your desktops if this
is a real concern at your company - software restriction can work well
although it can also be dangerous (play with this in a lab before
deploying). Try posting in microsoft.publicwindows.group_policy for more
help.


.



Relevant Pages

  • =?iso-8859-1?Q?Re:_New_Windows_2003_Cluster_-_MSI_=B4s_are_not_applied?=
    ... Are you only installing software to a computer? ... The assignment of application Previous Versions Client from policy Software Assign - Previous Versions Client succeeded. ... The install of application Previous Versions Client from policy "whatever" - Previous Versions Client failed. ... This has to be done on both the share permisions and the ntfs permisions. ...
    (microsoft.public.windows.group_policy)
  • Re: error 0x8007007e
    ... Attempt to access the Windows Update site again. ... Do you have any web "accelerators", download ... >> Asynchronous Install completed startup ... >> Installing SOFTWARE item from publisher com_microsoft ...
    (microsoft.public.windowsupdate)
  • Re: error 0x8007007e
    ... Here are some entries from the windows update.log ... Downloading file ... Asynchronous Install completed startup ... Installing SOFTWARE item from publisher com_microsoft ...
    (microsoft.public.windowsupdate)
  • Re: error 0x8007007e
    ... " This issue can be resolved by enabling "Use HTTP 1.1 through proxy ... Attempt to access the Windows Update site again. ... > Asynchronous Install completed startup ... > Installing SOFTWARE item from publisher com_microsoft ...
    (microsoft.public.windowsupdate)
  • Re: Installing software in TS session
    ... All of my updates are done on both the server and client machine. ... I need to install a proprietary software to each terminal services profile ... installing software on terminal server is NOT same as other windows ...
    (microsoft.public.windows.terminal_services)