PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Hébergement serveur > ms.win.server.scripting > Making domain users local admins
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
Making domain users local admins

Réponse
 
LinkBack Outils de la discussion
Vieux 24/11/2007, 15h39   #1
Laphan
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Making domain users local admins

Hi All

I had a problem whereby the teachers couldn't use their home internet on
their 'domain-linked' laptops because of the limited access that they get.

Didn't want to make them part of the domain admins groups so somebody
suggested that I add the domain users group (which they are part of) to the
laptop's local admins (ie via Computer Management / Users&Groups/ Groups/
Admins.

Is this OK to do?

They seem to be able to get to the TCP/IP bit now, but what other 'doors'
have I opened to the blessed teachers by doing this?

Can they install/uninstall software now???

Thanks

Laphan


  Réponse avec citation
Vieux 24/11/2007, 15h48   #2
Pegasus \(MVP\)
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins


"Laphan" <admin@DontSpam.com> wrote in message
news:exPmZfqLIHA.4456@TK2MSFTNGP03.phx.gbl...
> Hi All
>
> I had a problem whereby the teachers couldn't use their home internet on
> their 'domain-linked' laptops because of the limited access that they get.
>
> Didn't want to make them part of the domain admins groups so somebody
> suggested that I add the domain users group (which they are part of) to
> the
> laptop's local admins (ie via Computer Management / Users&Groups/ Groups/
> Admins.
>
> Is this OK to do?
>
> They seem to be able to get to the TCP/IP bit now, but what other 'doors'
> have I opened to the blessed teachers by doing this?
>
> Can they install/uninstall software now???
>
> Thanks
>
> Laphan
>


They will be able to install/modify/uninstall anything on their
PCs and they have full access to all files and folders. They
have no general access to server-based files but you should
test this to be on the safe side.


  Réponse avec citation
Vieux 24/11/2007, 17h02   #3
Kerry Brown
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins

With XP there is almost no other way to allow users to use their computer
for normal use. With Vista this will change somewhat with UAC as programs
are updated to be Vista compatible.

--
Kerry Brown
Microsoft MVP - Shell/User
http://www.vista.ca


"Laphan" <admin@DontSpam.com> wrote in message
news:exPmZfqLIHA.4456@TK2MSFTNGP03.phx.gbl...
> Hi All
>
> I had a problem whereby the teachers couldn't use their home internet on
> their 'domain-linked' laptops because of the limited access that they get.
>
> Didn't want to make them part of the domain admins groups so somebody
> suggested that I add the domain users group (which they are part of) to
> the
> laptop's local admins (ie via Computer Management / Users&Groups/ Groups/
> Admins.
>
> Is this OK to do?
>
> They seem to be able to get to the TCP/IP bit now, but what other 'doors'
> have I opened to the blessed teachers by doing this?
>
> Can they install/uninstall software now???
>
> Thanks
>
> Laphan
>
>


  Réponse avec citation
Vieux 24/11/2007, 18h51   #4
Florian Frommherz [MVP]
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins

Howdie!

Laphan schrieb:
> Didn't want to make them part of the domain admins groups so somebody
> suggested that I add the domain users group (which they are part of) to the
> laptop's local admins (ie via Computer Management / Users&Groups/ Groups/
> Admins.
>


Don't make them admins. That's way too much. If those laptops are on
Windows XP, you can use the "Network Operators" group to let them change
IP and network configuration.

cheers,

Florian
--
Microsoft MVP - Windows Server - Group Policy.
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
  Réponse avec citation
Vieux 24/11/2007, 18h58   #5
Laphan
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins

Hi

Tried that and it wouldn't work.

As soon as they got the network components list, ie Client for Networks,
TCP/IP, etc, they couldn't click into the TCP/IP entry to go and edit it.

Although I'm saying that I made them network operators via Active Directory
control panel on the server!

Should I have made the teachers network operators on the Local Admin setup
of the laptop?

Thanks

Laphan

"Florian Frommherz [MVP]" <florian@PLEASELEAVETHISOUT.frickelsoft.net> wrote
in message news:uRFrsKsLIHA.4688@TK2MSFTNGP06.phx.gbl...
Howdie!

Laphan schrieb:
> Didn't want to make them part of the domain admins groups so somebody
> suggested that I add the domain users group (which they are part of) to
> the
> laptop's local admins (ie via Computer Management / Users&Groups/ Groups/
> Admins.
>


Don't make them admins. That's way too much. If those laptops are on
Windows XP, you can use the "Network Operators" group to let them change
IP and network configuration.

cheers,

Florian
--
Microsoft MVP - Windows Server - Group Policy.
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.


  Réponse avec citation
Vieux 24/11/2007, 19h09   #6
Florian Frommherz [MVP]
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins

Howdie!

Laphan schrieb:
> Although I'm saying that I made them network operators via Active Directory
> control panel on the server!
>
> Should I have made the teachers network operators on the Local Admin setup
> of the laptop?


Of course you need to make those changes on the client computers. Have a
look at "Restricted Groups":

http://technet2.microsoft.com/window....mspx?mfr=true
http://www.frickelsoft.net/blog/?p=13

cheers,

Florian
--
Microsoft MVP - Windows Server - Group Policy.
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
  Réponse avec citation
Vieux 24/11/2007, 23h07   #7
\RemS
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins



"Florian Frommherz [MVP]" wrote:

> Howdie!
>
> Laphan schrieb:
> > Although I'm saying that I made them network operators via Active Directory
> > control panel on the server!
> >
> > Should I have made the teachers network operators on the Local Admin setup
> > of the laptop?

>
> Of course you need to make those changes on the client computers. Have a
> look at "Restricted Groups":
>
> http://technet2.microsoft.com/window....mspx?mfr=true
> http://www.frickelsoft.net/blog/?p=13
>
> cheers,
>
> Florian
> --
> Microsoft MVP - Windows Server - Group Policy.
> eMail: prename [at] frickelsoft [dot] net.
> blog: http://www.frickelsoft.net/blog.
>


Assuming you are using cached credentials.

It is recommended to create a new security group in AD and add that group to
the local groups (using 'Restricted Groups'), rather then adding the user
account directly to the local groups.
Then use ADU&C to controll the members of the new AD group, by adding or
deleting users to this group.
once the AD group is added to the specific local group, Users just have to
logof and logon at office, after you added them to the group in AD.

Go through this thread about 'Restricted groups'
http://www.petri.co.il/forums/showthread.php?t=12489

Alternatively you can controll the members of local groups by script:
http://windows.stanford.edu/Public/I...p.html#Scripts
In this case you add the new AD security goup to the local groups by
computer startup script, instead of using the 'Restricted Groups'-computer
configuration policy.

If the users do not use cached credentials, then use the local account the
users use to logon at home (or use a startupup script to add a new local user
account to the computers). Then add that account to the group, you can do
that also by using Restricted Groups.


\Rems
  Réponse avec citation
Vieux 25/11/2007, 01h00   #8
Al Dunbar
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins


"Florian Frommherz [MVP]" <florian@PLEASELEAVETHISOUT.frickelsoft.net> wrote
in message news:uRFrsKsLIHA.4688@TK2MSFTNGP06.phx.gbl...
> Howdie!
>
> Laphan schrieb:
>> Didn't want to make them part of the domain admins groups so somebody
>> suggested that I add the domain users group (which they are part of) to
>> the laptop's local admins (ie via Computer Management / Users&Groups/
>> Groups/ Admins.
>>

>
> Don't make them admins. That's way too much. If those laptops are on
> Windows XP, you can use the "Network Operators" group to let them change
> IP and network configuration.


And don't add a generic AD group like "Domain Users" to *any* group with
privileges on a workstation. This is why "\RemS" recommended you create a
new AD group for the purpose - so that it can be managed.

/Al

> cheers,
>
> Florian
> --
> Microsoft MVP - Windows Server - Group Policy.
> eMail: prename [at] frickelsoft [dot] net.
> blog: http://www.frickelsoft.net/blog.



  Réponse avec citation
Vieux 05/12/2007, 10h53   #9
Mohamed Garrana
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins

hey laphan
have you tried settings TCP/IP alternate configuration for them to use at home
what exactly is that they want to do at home and they cant? changing their
tcp/ip configuration ?

"Laphan" wrote:

> Hi
>
> Tried that and it wouldn't work.
>
> As soon as they got the network components list, ie Client for Networks,
> TCP/IP, etc, they couldn't click into the TCP/IP entry to go and edit it.
>
> Although I'm saying that I made them network operators via Active Directory
> control panel on the server!
>
> Should I have made the teachers network operators on the Local Admin setup
> of the laptop?
>
> Thanks
>
> Laphan
>
> "Florian Frommherz [MVP]" <florian@PLEASELEAVETHISOUT.frickelsoft.net> wrote
> in message news:uRFrsKsLIHA.4688@TK2MSFTNGP06.phx.gbl...
> Howdie!
>
> Laphan schrieb:
> > Didn't want to make them part of the domain admins groups so somebody
> > suggested that I add the domain users group (which they are part of) to
> > the
> > laptop's local admins (ie via Computer Management / Users&Groups/ Groups/
> > Admins.
> >

>
> Don't make them admins. That's way too much. If those laptops are on
> Windows XP, you can use the "Network Operators" group to let them change
> IP and network configuration.
>
> cheers,
>
> Florian
> --
> Microsoft MVP - Windows Server - Group Policy.
> eMail: prename [at] frickelsoft [dot] net.
> blog: http://www.frickelsoft.net/blog.
>
>
>

  Réponse avec citation
Vieux 14/01/2008, 19h09   #10
Trevor Sullivan
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Making domain users local admins

Adding your "Domain Users" group to all the local admin groups on your
systems is asking for trouble. Think about it ... if a virus executes as
a user on one system, that virus will automatically have full rights to
remotely install itself on everyone's system. At **LEAST** just add
individual users to the admin group, if you're going to do it at all,
but I would put some effort into investigating how to get around the
admin rights problem altogether.

Aaron Margosis has some excellent blog entries about working around LUA
bugs.

----------------
Trevor Sullivan
Systems Engineer

Laphan wrote:
> Hi All
>
> I had a problem whereby the teachers couldn't use their home internet on
> their 'domain-linked' laptops because of the limited access that they get.
>
> Didn't want to make them part of the domain admins groups so somebody
> suggested that I add the domain users group (which they are part of) to the
> laptop's local admins (ie via Computer Management / Users&Groups/ Groups/
> Admins.
>
> Is this OK to do?
>
> They seem to be able to get to the TCP/IP bit now, but what other 'doors'
> have I opened to the blessed teachers by doing this?
>
> Can they install/uninstall software now???
>
> Thanks
>
> Laphan
>
>

  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 02h35.


Édité par : vBulletin® version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,25451 seconds with 18 queries