General discussion
December 13, 2002 at 08:47 PM
parameshst

Restrict Local Admin from Domain rights

by parameshst . Updated 23 years, 6 months ago

Hi…

I have given my Domain Users(Win2k)the admin rights to their local systems(win2k pro) by going to Active Dir users and comps–>computers–>right click on the client computer –> manage—>groups and the added the user of that system to the administrators group so that they can manage their system for installing software, iis admin,…etc.
Now the users are able to change the security settings on the local drives. They are infact able to get access to add or remonve domain users permisions settings without entering the domain password.
Probably the Domain Admin rights are inherited to the local Admin group.
How to over come.

Any ideas… please help,

Thanks & Regards,
Parameshwar

This discussion is locked

All Comments