Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Prevent domain users from sharing?

Status
Not open for further replies.

AlphaMale

MIS
Aug 14, 2001
24
ZA
Heres the scenario:

Win2k AD and GP.
Clients on Win2k Pro.
Domain users have admin privi on their local Win2k Pro workstations.

Now, I want to prevent users from creating shares on their workstations (even tho they have local admin privi). Only Domain Admins should have rights to create shares.

Is there a way I can establish this with the GP? I've played around with the GP > User conf > Admin templates > Windows comps > Netmeeting > Application sharing >, but to no avail.

TIA
 
Do your users absolutely need local Admin privileges?
 
The local admin privis were set by the previous sysadmin, and while the domain was still on NT4. I've since migrated the domain to Win2k, but I've inherited almost a 1000 workstations with users that have local admin privi.

Are you pointing me in that direction maybe, that I should revoke their local admin rights?
 
It seems that the previous SysAdmin did not care about domain users having Admin rights. I only give users what they need to do their job and I rarely use the default settings when creating groups and users. Remember, give the users the least amount of rights and only grant higher access if they cannot do their job. You are the man and the decision is yours. Have fun.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top