I got a windows 2000 domain
Have created some users in it.
On workstations either win2k pro or WinXP is running
Now the domain users that i have created are simple users, with all default settings.
No group policy of any kind has yet been applied
Now as the users are made part of simple users group they donot get the permission to install any software on their computers.
I got to know of a method and applied that, in which a user is made part of local administrators account by going into groups in computer management and adding the user in their.
The users get full privilages but then they also are able to access the domain controller with full rights. They are able to access the hidden shares, which i want to prevent.
What has to be done in this regard?