Solved

all users being in the local admins group

Posted on 2004-03-23
6
167 Views
Last Modified: 2010-04-13
Hi all,

Just looking to get some opinions on normal users being local admins on their pc's. we have a development center with 500 people and most of them are local admins because they need to install software etc.. what do you think is good practice for something like this? everyone powerusers?

many thanks

tdvit

0
Comment
Question by:tdvit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 15

Assisted Solution

by:Rob Stone
Rob Stone earned 60 total points
ID: 10656286
If its possible it would be better to have everyone as Power Users, although some apps require admin rights to install.  You could use an GPO to publish software to specific users? That way you will know whats being installed and when without them being admin users.

If you want to change the admin groups on all the PC's you can use NetDom.exe.
0
 
LVL 21

Expert Comment

by:jvuz
ID: 10656676
I don't like to give admin rights to the users, because you never know what they gonna  install. I know not everyone will abuse those rights, but there are too many people who abuse that right.
0
 

Author Comment

by:tdvit
ID: 10656695
i hear you jvuz but what can you do if you have to facilitate users.  if power users doesnt do it, whats the alternative.  We as IT people have to bite the bullet and just give it to them.  from everything that I am reading there doesnt seem to be a workable alternative.
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 
LVL 15

Assisted Solution

by:Rob Stone
Rob Stone earned 60 total points
ID: 10656724
What about creating a install account thats in the local admins and then tell them to use the RunAs option to install apps that need admin rights.

You can also audit logon's for a week or so to see who is logging on to their PC's with that user and you can then tell them not to do so.

That or get a procedure where you remote control their PC and put in the user name/password yourself when they need to install the software, but they would need to inform you when they need software installing.

In the long run, its better to have managed systems by the IT dept so you know whats being installed, then if things go wrong you have a better idea of fixing it.
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 40 total points
ID: 10657453
I assign local admin rights usually. To me only have local administrator rights doesnt pose any threat in my eyes. A lot of it depends on the environment of course. A development company I would do it where I know the computer liiteracy would be high enough to avoid any stupidty (deleted a key folder etc) but would restrict admin right from those who do not need it (accountants, admin staff etc). Other environments I would block it completely and leave it at just regular users (like in a Realtor company with public use computers)

0
 
LVL 21

Expert Comment

by:jvuz
ID: 10657683
If the users hafe admin rights, they can install everything, also software where you need a license for. If its freeware, I don't think it's a problem.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Popular third-party chat platforms like Slack, Discord, and Telegram are just a few of the many new productivity applications that are being hijacked by cybercriminals to create command-and-control (C&C) communications infrastructures for their malw…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question