How to manage Laptop users policy in term of local administrator right

Posted on 2006-06-02
Last Modified: 2013-12-03
Is there a way whereby a laptop user logon onto domain, the local right will be given as Power User. Once disconnected from office network, the local right will change from Power User to local administrator. Note: this use domain username and password logon without creating another same username in local machine.
Question by:chekfu
    LVL 3

    Expert Comment


    I'm posting a response here mainly because I want to see what the answer is going to be.  Sorry I do not have one.

    checkfu . . . why do you want to do this . . . if you don't mind me asking?

    LVL 1

    Author Comment

    Set local administrator for any user is not allow. There is no issue for desktop computer user. Only, the laptop user find many inconvience to operate outside office network such as they cannot perform program installation, or cannot change setttings because it is dimmed

    Is there a way to resolve this management scenario? How to do? Please advice!
    LVL 38

    Accepted Solution

    We have used several different methods to combat problems such as this... Laptop users sometimes need to assign an IP statically, or change something in the network settings for example, and a power user cannot do this. There are even occasions where software will need to be installed suddenly that cannot be installed by a power user.

    If you have a 24x7 helpdesk, the user can call the help-desk and have the helpdesk VNC, or remote desktop to the PC and do what is needed, this however won't always work as again the user may need to have network settings changed befor they can even get an IP, so remote-control software won't work in this case, and the HD will have to give the user the local admin pass and walk them through the process. Or the firewall needs modified etc..

    If there are common task's that the user needs to preform, you can try the run-as VBS scripts listed here: The network settings and control panel however cannot be accessed using this method however. There are various control panel applets that will work with this method, however not all of them can be called this way.

    M$ has written several utilities that can help you run apps with runas, the first uses runas to run apps in a lower privileged account while be logged on as a higher privileged account
    The second, is not likely to be used but I should mention it anyway... it requires the user to know the local admin pass...

    This  one can be used by trusted persons... meaning you have to trust them enough not to abuse the power it gives...
    There is also ProcessExplorer/PsExec:
    And runAs has a "savecred" switch that is really a big hole... as it will allow anything to be run as the admin if your not careful...

    As always, security is a tradeoff between ease of use, and following your own guidelines. Security is a process not a program, so you have to keep that in mind. If you think your users may be too "savvy" and figure out how these tools work or how to abuse them, then you'll need to put inplace other checks, like a logon script that can alert you to approved software being installed...

    Featured Post

    Enabling OSINT in Activity Based Intelligence

    Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

    Join & Write a Comment

    When the confidentiality and security of your data is a must, trust the highly encrypted cloud fax portfolio used by 12 million businesses worldwide, including nearly half of the Fortune 500.
    Healthcare organizations in the United States must adhere to the guidance of both the HIPAA (Health Insurance Portability and Accountability Act) and HITECH (Health Information Technology for Economic and Clinical Health Act) for securing and protec…
    Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    755 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now