?
Solved

Local Admin User -- deny additional local admins ?

Posted on 2016-08-09
6
Medium Priority
?
71 Views
Last Modified: 2016-08-12
How can I do something like the below "DESIRED"
solution without allowing step #6+ to happen since
I want to FORCE users to login as POWERUSER when doing
installs to help prevent accidentally installing
something without being aware of it (i.e. virus) ?

Server = Windows Server 2012 R2 with AD
Client = Windows 10 Pro
--------------------------------------------------------------------------------------------------
Current
 1. user gets error message when
    trying to install something
 2. user calls me
 3. I DameWare into machine
 4. I login to Windows 10 Pro as me
 5. I do the install
--------------------------------------------------------------------------------------------------
Desired
 1. user gets error message when
    trying to install something
 2. user logs into Windows 10 Pro
    as "USER=POWERUSER, PASS=something"
 3. user does install
 4. user logs back into
    their regular account
 5. install works
 6. user does above desired step #2 again,
    doing the below to grant their
    USER=LastNameFirstInitial ADMIN
    rights all the time
       ** Control Panel
       ** Administrative Tools
       ** Computer Management
       ** Local Users and Groups
       ** Groups
       ** Administrators
       ** Add
       ** USER=LastNameFirstInitial
0
Comment
Question by:finance_teacher
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 6

Accepted Solution

by:
jpquonce earned 1000 total points
ID: 41749103
Have them hold shift and right click the executable and do RUN AS DIFFERENT USER. Then put in USERNAME and PASSWORD of your desired power user credentials.
0
 

Assisted Solution

by:finance_teacher
finance_teacher earned 0 total points
ID: 41749160
The above solution does not disallow above step #6+

How can I setup an account that disallow above step #6+ ?
0
 
LVL 6

Assisted Solution

by:jpquonce
jpquonce earned 1000 total points
ID: 41749183
Try adding a GPO for their USER to disable it and see if that works:
 User Configuration\Administrative Templates\ Windows Components\Microsoft Management Console\Restricted/Permitted snap-ins-> disable Computer Management

There is also disable Local Users and Groups
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
LVL 5

Assisted Solution

by:Jambon316
Jambon316 earned 1000 total points
ID: 41749969
yeah take them out of the local admin group
0
 
LVL 5

Assisted Solution

by:Jambon316
Jambon316 earned 1000 total points
ID: 41749981
looking at this again, if a user account has rights to install stuff then it won't stop malware installs, install rights are install rights , the system can't tell the difference between dodgy software and good software.

strictly speaking , your current method is kind of best practice...
>user needs software
> user contacts admin
>admin can tell good from bad and then installs if good
>users are users and should not be admin

how much software do your users want installed anyhow? surely they'd have established line of business software installed and after that very little else ... or trouble will surely follow generally...everytime I've seen all users getting admin rights on the network, generally cryptovariant attack will inevitably follow and devastate due to the increased rights of the infected.

I know it seems like a pain, but your current method is better.
0
 
LVL 5

Assisted Solution

by:Jambon316
Jambon316 earned 1000 total points
ID: 41749989
or try SCCM as a solution - bit of a task installing and configuring initially but software deployment is so easy once it's working... usually 2 or 3 clicks gets a program installed where it should be , no fuss. Loved being an admin on it, but never installed and configured it though.

worth looking into though if this is an issue
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question