Avatar261
asked on
Denying Administrator The Right To Change Computer Name
I want to deny a local administrator the right to be able to shut down a server and change it's computer name or remove it from the domain.
I have created a local group called Shutdown Users and edited the local security policy setting "Shut down the system" and this works a trat.
However i cannot find a setting to be able to do similar to stop them changing the computer name.
How can i acomplish this?
I have created a local group called Shutdown Users and edited the local security policy setting "Shut down the system" and this works a trat.
However i cannot find a setting to be able to do similar to stop them changing the computer name.
How can i acomplish this?
ASKER
This is not a domain admin.
I am talking about just a local admin on a server.
I am talking about just a local admin on a server.
Is this a domain server or a Stand alone server?
There is an alternative. It is a GPO to deny "log on locally". Are you interested?
There is an alternative. It is a GPO to deny "log on locally". Are you interested?
ASKER
Hmm, it is a domain server.
How does the deny log on locally stop them renaming the computer?
How does the deny log on locally stop them renaming the computer?
Just like you create a domain policy or group policy, you can create a local policy. It all depends on what you want to do.
Go to the local policy MMC snapin and add a user policy to that user. I don't know if there is a policy to prevent from changing computer name or prevent from logoff. That's something that someone more familiar with GPOs can tell you.
Go to the local policy MMC snapin and add a user policy to that user. I don't know if there is a policy to prevent from changing computer name or prevent from logoff. That's something that someone more familiar with GPOs can tell you.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Solution would be to NOT give out the admin password and only give out a secondary login that has delegated rights.
If someone else has the admin password that it not authorized then you have bigger issues.
solve that first then lock everything down.