Disable logon to XP without disabling or locking account?



We have a couple domain accounts that are members of the local
Administrators group on all our workstations. (Our domain users are
Power Users.) We use these accounts to log in and install programs
and things that Power Users cannot. A while ago one of the IT created
another account and added it to the group with the intent of using the
account for Run As... installation scripts and things of that nature.
Pretty soon a couple of domain users have read the batch files and
taken the password for that account and are now using it to log on to
their workstations and install software. They only call IT after they
have ruined their registry or downloaded a virus. The Run As...
account has been very helpful and a huge time saver but opened up this
security hole. It would not be so much of a problem if we could
restrict log on from the account but still use it to "Run As..."
Unfortunately if I modify the Log On To... under the account
properties in Active Directory the Run As... will not work unless the
the account is also allowed to log on. Is there anything we can do to
prevent the account from logging on to Windows XP, but still be able
to Run As...? Thanks.
.



Relevant Pages

  • Re: OWA distorted
    ... I have added the domain users, users, Authenticated Users in the securit ... on the bin folder if that will help in any way. ... if you hadn't changed the account used for Anonymous Access. ...
    (microsoft.public.exchange.admin)
  • Re: ADAM : Install using Domain users as Admin rights issue
    ... If you create a partition on the 2nd instance after installing the 2nd ... then by default this partition is only hosted by the 2nd instance. ... > account is not allowed ... >>that you've tried both a domain users account and a local ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain account iwth restricted rights
    ... That was probably added to account for the change above. ... The Domain Users causes the "Logon Locally" right to be present ... So you need both different permissions and different rights perhaps. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Controlled user access
    ... > If I setup an account for a vendor to come in and look at their software, ... Not if your shares are correctly setup -- or you can use ... He IS a domain users so you are granting him access to ... It is possible to take an account OUT of Domain Users ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local System Account & Network Access
    ... account on a domain computer. ... Keep in mind that services that log on as Local System have ... membership but they do have a bearing on what a user/computer has access to ... You said that the share has only read for domain users group ...
    (microsoft.public.security)

Loading