Solved

Limit Local Admin Rights

Posted on 2014-11-04
5
325 Views
Last Modified: 2014-11-07
Most of my windows users have the local admin access in order to properly run two major/custom applications.
This means they can also download/install other programs (including viruses) and make changes to many things.

I want to know if it is possible to limit admin access using windows or some other application?

Thanks, your help is much appreciated.
0
Comment
Question by:cP6uH
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 96

Accepted Solution

by:
Experienced Member earned 500 total points
ID: 40421830
Administrators have the keys to the kingdom and uninformed administrators wreck computers.

RULE 1. No user is administrator .
RULE 2. ALL users have UAC turned on.

Not much else you can do with Windows.

You can implement Power Broker for Windows from Beyond Trust. That provides the granular approach you want, but is an add-on product to Windows and your server.

http://www.beyondtrust.com/PowerBroker-Desktops-Windows-Edition.aspx?section=PowerBroker-Desktops-Windows-Edition
0
 
LVL 9

Expert Comment

by:dlb6597
ID: 40422170
I've been able to get many apps working by using process monitor from sysinternals/microsoft. It records all file and registry access and lets you filter on access denied. I launch process monitor, setup filters on the specific app and look for access denied in the log...then grant the appropriate permissions to those registry keys and or file locations to allow the applications to run without local admin privileges. It takes some time, but it is worth it in the end.
0
 
LVL 55

Expert Comment

by:McKnife
ID: 40422705
If security matters to you, avoid software that requires admin accounts.
John's advice, powerbroker desktop, is capable of doing what you require, empowering standard users to use selected applications with higher privileges securely - windows alone is not.
0
 

Author Closing Comment

by:cP6uH
ID: 40429064
I will adjust the UAC settings on each workstation, and get a quote for Power Broker from Beyond Trust.
Thank you.
0
 
LVL 96

Expert Comment

by:Experienced Member
ID: 40429069
@cP6uH  - Thanks for the update and you are very welcome.
0

Featured Post

Salesforce Made Easy to Use

On-screen guidance at the moment of need enables you & your employees to focus on the core, you can now boost your adoption rates swiftly and simply with one easy tool.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Article by: Justin
In light of the WannaCry ransomware attack that affected millions of Windows machines, you might wonder if your Mac needs protecting. Yes, it does and here is how to do it.
The recent Petya-like ransomware attack served a big blow to hundreds of banks, corporations and government offices The Acronis blog takes a closer look at this damaging worm to see what’s behind it – and offers up tips on how you can safeguard your…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question