We have a situation where a number of our NT/2000 Workstation users on the LAN need to have local Administration rights to their machine. At the same time we want to prevent people from installing software themselves.
I know that through the default domain policy we can shut off certain way of the users initiating an install of a program, yet that still does not stop them from downloading programs and installing them or popping in a CD and manually starting an install…
The first thought might be to simply take away local admin rights…but certain software we have onsite will not run without local admin rights for the user…
Any thoughts on how to tackle this issue of dis-allowing people with local admin rights from installing software?