1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Deny desktop admin rights to Domain Admins?

Discussion in 'Security and Privacy' started by perdenab, 2005/01/27.

Thread Status:
Not open for further replies.
  1. 2005/01/27
    perdenab

    perdenab Inactive Thread Starter

    Joined:
    2005/01/27
    Messages:
    2
    Likes Received:
    0
    I would like to prevent our domain admin users from having any admin privileges on their own desktops.

    This is in order to prevent IE and other apps running with admin privileges on their desktops.

    If anyone does admin work, I want it to be using a different, privileged account, using RUNAS or a remote desktop connection of some kind (or the local admin user, from the console.)

    Is there a way to deny domain admin users this specific privilege?
     
  2. 2005/01/27
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    What problem are you trying to fix - other than having way too many domain admins?
     
    Newt,
    #2

  3. to hide this advert.

  4. 2005/01/28
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    I would like to prevent our domain admin users from having any admin privileges on their own desktops.

    In the NT world, you cannot *prevent* a domain admin from doing adminy things to a machine joined to a domain. You can put in a bunch of speed bumps, but you arent going to prevent them if they are motivated.

    I have two suggestions, create twin accounts for admins, Joe and JoeAdmin. Setup a bunch of runas shortcuts for MMC and such, as you said. This is the more common way of doing it.

    Take domain admins out of the local administrators group on thier desktops. (noting they could put it right back in after you leave).
     
  5. 2005/01/28
    perdenab

    perdenab Inactive Thread Starter

    Joined:
    2005/01/27
    Messages:
    2
    Likes Received:
    0
    What I am looking for is for the policy to say, "this user is normally a full admin, but on this workstation (or set of workstations) he is just an unprivileged user ".

    I realize an admin can change this back. The purpose of the change is to permit our domain admins in their daily work to browse the internet, run Outlook etc without the concern that spyware, malicious emails etc will install/run with admin privileges.

    My preferred solution to this, longer term, is to simply create a second domain with the same scope as our existing one, but containing only our admin users, then remove admin privs from users in the first domain. Admin "Joe" would then have accounts in both domains. He'd do his normal work as \\DOMAIN1\Joe, but for admin work would do RUNAS etc etc as \\DOMAIN2\Joe.

    What I am looking for is an interim (and admittedly voluntary) fix until this can be done.

    Thanks, and sorry for the lack of clarity/context in my original post.
     
  6. 2005/01/28
    ericiga

    ericiga Inactive

    Joined:
    2004/11/19
    Messages:
    76
    Likes Received:
    0
    I'm with Joe the only real way to do this is to have two accounts for your admins. One they use for their everyday work and one with domain admin rights for when working on the servers or where ever they need those rights.

    We use First Initial Last Name for all of our accounts, and then the accounts for domain admin access also include our middle initial.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.