We are currently looking to block users on our network from being able to install software without the IS departments knowledge. One idea we have come up with is to use a global policy to allow only the newtork admins to do software installs. We could simply remove all users from the local machine admin groups, but some of our software will not run unless the user is a local admin. Does anyone know if it is possible to set a global policy to allow only the network admins to do installs, and how one would accomplish this?
Thanks in advance,
Start Free Trial