All of our users are members of the local Administrators group on their XP machines.
We want to revoke their rights to a point that they won’t be able to manipulate services or delete/change administrator accounts on the machine.
Since they currently have full rights, many of them have disabled our enterprise admin account on their box.
To minimize affect on the users, we’d like to be able to basically have them in a group that has Administrator rights with service control and user account control removed.
Is this possible?
Thanks,
Greg