Solved

remote shut down of machines

Posted on 2013-01-21
7
255 Views
Last Modified: 2013-01-25
Hi there,
Running server 2008 R2 domain, with window 7 prof clients.  Many users came today complaingint that someone is remotely shutting their machines down.  What can be safely set into the AD so that no one can shutdown my client machines.
THanks
0
Comment
Question by:amanzoor
  • 3
  • 2
  • 2
7 Comments
 
LVL 1

Assisted Solution

by:cgitek
cgitek earned 100 total points
Comment Utility
Ok so you will need to look here first and create your GPO. I believe this is the same for W7.

http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/539.mspx?mfr=true

You will also want to make sure you change the local Administrator password or disable local logons again using GPO to prohibit someone using a local account to reboot the workstation.
0
 
LVL 27

Expert Comment

by:Jason Watkins
Comment Utility
I would make sure this setting is set at a domain level GPO and not on the local GPO
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
My domain level and domain controller level GPOs are all fine, the problem I have found is that on all these laptops, the users belong to a group called 'student' and this groups has been added to the local administrators group.  I think this is the reason they can shut down each others machines.  If I remove this groups from the local administrators group then these users cannot install any apps, or software.  What can I do?  help
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 27

Accepted Solution

by:
Jason Watkins earned 400 total points
Comment Utility
In the domain or local GPO you can control exactly which users can or cannot shutdown the computer.

Computer Configuration \ Windows Settings \ Security Settings \ Local Policies \ User Rights Assignments \ Shut down the system

Change this to be only one group or user and you will be all-set.
0
 
LVL 1

Expert Comment

by:cgitek
Comment Utility
Just create a special group and make the actual administrator account the only member of that group...assign using the above method I and Firebar mentioned and you're done.
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
firebar and cgitek,
By putting assigning these GPO settings, will the laptop users will be able to shut their own machines down or no?  As a rule they should be able to shut down their own laptops and not anyone else?
0
 
LVL 27

Expert Comment

by:Jason Watkins
Comment Utility
To do what you have described, a local GPO would have to be used. On each machine, simply add the user who should be able to shut down the computer, to the GPO.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
LDAP and ADFS 1 20
cisco switch stacking 6 29
Printer Settings 3 58
VBS Script not working correctly. 1 13
Resolve DNS query failed errors for Exchange
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now