Link to home
Create AccountLog in
OS Security

OS Security

--

Questions

--

Followers

Top Experts

Avatar of techieguy_100
techieguy_100

Deny local admin accounts rights to install
We are in an active directory environementwindows server 2003, all users are members of the local admin groups on their computers (thanks to Oracal).  I want to deny members of  local admins the right to install software, download software to their local drives.  Only the domain administrator is to have this right.

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of iamsamiamsam🇺🇸

Are the users computers running XP Pro or Vista Business? If so why not set them up to join a domain? Unless you are over slow connections, then replication and propagation time could take a while.

Since you already have Active Directory installed, you could create an OU called Limited Users or something similar and add the appropriate users in that OU then utilize group policy snap-in to create a policy of not allowing software installation?
If you have fewer workstations to manage, you will probably have to edit the settings in each of them and move them to a different group than local admin.

Avatar of techieguy_100techieguy_100

ASKER

The users are using windows xp pro, I was looking in the group policy, but didn't see anything in there that would do the trick.

Avatar of Toni UranjekToni Uranjek🇸🇮

Hi!

There is no way to prevent members of local administrators group to install software. Actually there is no way to prevent them from doing anything. You should be looking at your problem from different point of view. Why does application need local administrator's permission and right to run? The proper way of solving this problem is to run application under standard user account with Process Monitor or similar program, which should identify resources (mainly registry and file system) to which access is denied. Change permissions on these registry keys and or file/folders only and remove users fromlocal administrator's group.

Process Monitor: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

HTH

Toni

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


That is the answer I was expecting, but not the one I was hoping for.

Glen

ASKER CERTIFIED SOLUTION
Avatar of Toni UranjekToni Uranjek🇸🇮

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

I only say this is partial because my problem isn't really solved, but it's probably as good as it's going to get.  Thanks
OS Security

OS Security

--

Questions

--

Followers

Top Experts

Operating system security (OS security) is the process of ensuring OS integrity, confidentiality and availability. OS security refers to specified steps or measures used to protect the OS from threats, viruses, worms, malware or remote hacker intrusions. OS security encompasses all preventive-control techniques, which safeguard any computer assets capable of being stolen, edited or deleted if OS security is compromised, including authentication, passwords and threats to systems and programs.