I don't run any networks with users having local admin right anymore. The messes they create are just increadible if they have admin rights. I would also not make them power users either as I have found that to be almost as bad. One way you can do this is to create an AD group for the purpose of granting Local Admin rights and make everyone a member of it. Then go to each machine (can be done remotely if you want) and remove the users from the local administrators group and add the AD group to the local Administrators group. End effect is nothing has changed, but you now have central control over who is or is not a local admin. Then you can work on removing the users from the AD group one at a time and resolving any software issues that come up. (most can be resolved by granting the Local Users group modify permissions to the problem software's folder in programs and files. Sometimes registry permissions to the problem software's registry keys are need as well. The other issues revolve around user's complaining that they can't be cowboys any more. You'll need to sell this to upper management to keep that from being too much of a problem.
Main Topics
Browse All Topics





by: mkline71Posted on 2009-10-28 at 08:12:48ID: 25684136
I'm all for taking away admin rights from users. In your case do you know why they have admin rights. Is there some sort of program that has to run under admin rights.
Hopefully in this day and age most programs don't need those rights.
The biggest con for you is going to be users that don't have full control and rights on their machines to do whatever they want. They are used to it and users like to complain.
The pro is a huge boost in security for you and your company and you control the desktops better so users can't install whatever they want and bring in that spyware and malware to their PCs.
Thanks
Mike