Login to computer through Admin Priviligies

Posted on 2016-11-08
Medium Priority
Last Modified: 2016-11-13
Hi all,
Just wanted a bit more insight on what are good and bads about logging into your work computer through admin privileges? means I know Admin account has lot of security privileges which can be exploited but is it really a big threat? I though having an Administrator user account (local/domain) is much bigger threat then this.
the reason to login to work computer with admin privileges is because to run applications like sccm, sql, sharepoint etc....
Question by:Leo
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 56

Accepted Solution

McKnife earned 1000 total points
ID: 41879984
Please read my article https://www.experts-exchange.com/articles/24599/Free-yourself-of-your-administrative-account.html where I show a way out of this dilemma.
And please explain "I though having an Administrator user account (local/domain) is much bigger threat then this." - I don't understand what "this" should mean as "this" should be the same.

Author Comment

ID: 41880001
Thanks for that article, now if I want to run a security audit across the network, is there a tool which can be used?
LVL 56

Expert Comment

ID: 41880006
What should that audit find out exactly?
 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks


Author Comment

ID: 41880012
Security holes in infrastructure , people who are using admin accounts to log on to there computers, any batch scripts which are running, service accounts whose passwords haven't been changed and general overall security health of infrastructure.
LVL 56

Expert Comment

ID: 41880026
Sorry, but this is really a totally different question, in fact, a set of questions. Please start new threads.
LVL 70

Expert Comment

ID: 41880050
Even if you leave attacks aside, you need to consider accidental actions like changing/deleting important files from protected areas. As non-admin you at least need another confirmation. On the other side, if you get conifrmation prompts for almost every action you have to take, they are useless ;-).
LVL 56

Expert Comment

ID: 41880053
"As non-admin you at least need another confirmation" - as admin, too, at least when UAC is at default level.
LVL 18

Assisted Solution

by:Mike T
Mike T earned 1000 total points
ID: 41881918

Short answer is that you need to ban logging in as the following on workstations:

domain admin
local admin

Users need restricted accounts. Power users need power accounts. No-one but no-one needs to be domain admin and logon to a workstation. Ever.
Even on servers limit it to a handful of trusted, authorised and competent (ideally certified) people. If they are not certified, go on training and get it. There's no excuse.

Always go for "least privilege" which means give people only enough permissions to do the things they are meant to be allowed and no more.

As for SCCM, well it does the permissions for you. You still don't need to logon as admin to make it work. In fact it's not going to help at all because it uses Local System which beats even domain admin anyway.

As for an auditing tool, create a new question and I'll try and remember what I've used in the past.

LVL 56

Expert Comment

ID: 41881923
I see you didn't ask any related questions, yet. You should. The additional questions reach far beyond this one.

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
What's worse than having your data encrypted by ransomware? Getting attacked by a so-called "wiper," which simply destroys the data and offers you no hope of ever seeing it again.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question