Solved

Restricting adding of local Users/Groups to Domain Admins

Posted on 2006-07-22
6
379 Views
Last Modified: 2010-04-18
Due to some uniqueness of my environment, I need to give domain users local Administrative access to some machines.  However one of the no-nos is for these local Adminstrators is to create local accounts, but often then do anyway.  How can I restict the creating of local accounts to Domain Admins only?

Environment: W2K3 Standard Servers, Windows XP-Pro clients
0
Comment
Question by:jchauncey60
6 Comments
 
LVL 1

Expert Comment

by:rimba_
ID: 17161403
hello,
what you can do is block the ejecution of mshta.exe (you can do this is the domain policies)

and for prevent the admins to run it from the run or the command using "control userpasswords2", block the run and the command in all the machines (this can be done in the domain policies as well)
0
 

Author Comment

by:jchauncey60
ID: 17161524
Thank you for your suggestion, however it did not seem to work.  I created a "test" account and added them to the local Administration group and was still able to add a new user and place that user into the local Administrator's group.

Just in case I misunderstood something, I am adding users from My Computer->Manage->Local Users and Groups.

Again, thanks for feedback.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17161743
the minute you add a user to the admin local group...they have these permissions

you can counter that with group policy to a point
Administrative Templates\Windows Components\Microsoft Management Console\Restricted/Permitted snap-ins\Computer Management
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 51

Expert Comment

by:Netman66
ID: 17161845
Very simply, create Restricted Groups for each local Group on the PC.  Enforce the membership of this group (use the Members section).

Now when a new local user is created, the account wants to belong to the Users local group - however, if you enforce this to contain only Domain Users then account creation should fail since the user cannot belong to any local groups (as defined in your GPO).

So you need to create Restricted Groups for:

Administrators - contain Domain Admins, the local Administrator and a new Security Group from the domain that contains the users that need Admin rights.  
Power Users - no members.
ec, etc.

Make sure to include the default members in these Groups since this policy will remove anything not explictly defined in your policy.

0
 
LVL 51

Accepted Solution

by:
Netman66 earned 250 total points
ID: 17161847
Oh, make sure you apply this to an OU where only the workstations live - you do not want this to apply to your servers.

0
 
LVL 1

Expert Comment

by:rimba_
ID: 17162792
try this:
go to windows/system32 there look for mshta.exe right click and select properties, there deny eveything to everybody and try to add a user again, if this works look the policy in the domain controller, maybe you re not restricting the access to this .exe correctly (you need to put the full path to it)
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now