How can I lockdown corporate laptops so users cannot modify add / remove programs while off doamin

I have around 22 users with laptops, all of which have local admin right on the domain and then on (local computer). Some of these users require access to use a card reader to program memory cards. Is there a way around this to allow them access to modify a card reader as I know this normally requires admin rights.

It is getting old having "know it alls" try to update graphics drivers and what not then jsut deleting them and having it corrupt the system and IE and other software.

Can anyone help me with this or recommend a workaround?

Thank you
manelson05Asked:
Who is Participating?
 
lacrewgaConnect With a Mentor Commented:
You can do this with Group Policy on the local machine. This link will explain how better than I can... http://support.microsoft.com/kb/307882
0
 
jbizzle979Commented:
This may help with hiding add/remove programs from them:

http://support.microsoft.com/kb/296962

They need to have admin rights to be able to access their card reader? I would think they could do that in another group, such as power users or something similar.
0
 
manelson05Author Commented:
lacrewqa, can I simply implement this locally on each laptop?
Or will this owrk if I make a Ad container called laptops, then move the computer fromt he main computer container and apply the gpo?
0
 
jbizzle979Commented:
It should work if you create the new container and apply the GPO to it.
0
 
manelson05Author Commented:
AWESOME!
I am loving GPO the more I play with it, the users have no control any longer, this is SWEET!
0
All Courses

From novice to tech pro — start learning today.