Solved

Restricting Domain Admin Accounts

Posted on 2014-04-03
4
53 Views
Last Modified: 2016-05-31
Hi,

We have IT and dev folks who currently are local administrators of their own systems.  We are looking to lock this down with standard user accounts as their main account and have a secondary admin account to use for administrative work.  

With that said, we would like for people to use this secondary admin account to do "run as" etc, but want to make sure to prevent users from trying to log onto machines locally with this admin account to use as their main account.

Can this be done?

Thanks.
0
Comment
Question by:mesadmin
  • 2
4 Comments
 
LVL 54

Accepted Solution

by:
McKnife earned 500 total points
ID: 39975799
No.
Running a program with different credentials interactively would have to be allowed - but that implies to have the privilege to logon locally, sorry.
Look at 3rd party software (privilege manager) or simply enforce and trust UAC
0
 
LVL 143

Expert Comment

by:Guy Hengel [angelIII / a3]
ID: 41626227
I've requested that this question be deleted for the following reason:

Not enough information to confirm an answer.
0
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 500 total points
ID: 41626228
I object.
Surely my comment has covered the facts and concluded: it's not possible, at least not if we assume the users want to abuse it.

If we however assume that users are nice and not technically savvy, yes, then there's even a way to prevent local logons: https://www.experts-exchange.com/articles/24599/Free-yourself-of-your-administrative-account.html holds it at the end: we can trigger account deactivation when users try to switch to the logon screen by using scheduled tasks as outlined.
0

Featured Post

Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
OfficeMate Freezes on login or does not load after login credentials are input.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question