Link to home
Start Free TrialLog in
Avatar of molard
molardFlag for United States of America

asked on

Prevent users from changing Administrator password

I work at a company with over 300 desktop computers and one Active Directory domain that I manage.  I have a specific account setup for my technical support guys so they can log onto each computer (only computers and not servers) and perform administrative actions.  For the purposes of this question, the user account is techsupport, it is a member of the Technical Support global group, which is a member of the Administrators local group on all computers.  The technical support guys have been changing the local administrator password and not telling anyone about it.  It's not a big deal though since I already have administrative access but it is a nuisance.  Also, if they know the administrator password on all client computers, then they could elevate privileges on their own computer and run scripts and other software that I might not want them to run in the first place.  I guess what I am looking for is the ability to do this through Group Policy or the Local Security Policy but I haven't found the option I want.  All computers are XP SP2 Pro and Windows Server 2003 SP2.  Thanks for the help.
Avatar of scrathcyboy
scrathcyboy
Flag of United States of America image

give users less than ADMIN rights, and they cannot change an admin password, period.
ASKER CERTIFIED SOLUTION
Avatar of Burns2007
Burns2007

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of johnb6767
And then to block the Linux boot disks, you have to setup the Boot Menu to HDD first, and block access to setup with a password....

Then to block that, you have to lock all the cases from them yanking the battery out and resetting the CMOS.........

Then you have to hire a gaurd to make sure they dont bring in Bolt Cutters.....

Then you have to.........

Sorry for the attempted humor, but bottom line is if they have an Administrative account, they can change the Administrator password. You can try all you want to prevent it, but What you really need is a Computer Usage Policy pertaining to this, and you need to have a few people fired once they break it.... That will prolly make them think twice about it.....

Audit account management
http://technet2.microsoft.com/windowsserver/en/library/42c66475-3346-428f-8faf-47a6611655ee1033.mspx?mfr=true

To help identify the people doing it.....

I have never been  afan of a single Support account. I prefer a secondary account with the needed rights in addition to the User Account they have, as it is easier to find the bungholes doing this type of things against your wishes....
Avatar of molard

ASKER

Great ideas, guys!  I have one question regarding setting the Administrator account to disabled.  If I had to use recovery console for XP, would I still be able to use the Administrator password to get in and run it?  Thanks again.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Enumerate the list of installed Hotfixes using WMI
http://windowsxp.mvps.org/qfe.htm

wmic qfe list full /format:htable >C:\hotfixes.htm

Please attach the hotfixes.htm here please.....
Sorry wrong thread...

:^)
Forced accept.

Computer101
Community Support Moderator