Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Prevent Local Admins Creating Accounts

Status
Not open for further replies.

gmail2

Programmer
Jun 15, 2005
987
IE
Hi All,

This may sound like a strange one but bear with me ! I've tried googling it but nobody else seems to have had this scenario before.

We have a few Application servers in our Enterprise on which we have had to give external vendors admin access in order for them to maintain/manage their application. Most of these guys are fine, but unfortunately there are 1 or 2 that only know their application and don't know much about windows, AD etc.

My fear is that they may decide to create a service account (for example) without telling anybody and running a service under that account (and giving it full admin rights - because that's all they know). We are using restricted groups to control admin access on that server, but these will only get refreshed every 16 hours. So potentially one of these guys could create an account, give it local admin rights, run the service with that account and everything's hunky dory. Then they go home happy, next day the restricted group kicks in, and all of the sudden the service stops working.

This is just one scenario. Another is alot more simple - that they might create a local account with admin access and use this to bypass any restrictions we may have set.

Either way, I don't want this happening. Our guidelines are clear - all accounts must be domain based, even service accounts.

I know I can restrict MMC's, set permissions on who can logon locally, interactively, logon as a service etc. But if possible I'd like to nip this in the bud and just prevent them from creating accounts in the first place. Does anybody know if this is possible? Or will I just have to control this with user rights assignments ?

PS: the above isn't an every day occurrance ... it's just a worse case scenario ... my mind goes into paranoia overdrive sometimes :)

Irish Poetry - Karen O'Connor
Irish Poetry and Short Stories - Doghouse Books
Garten und Landschaftsbau
 
Other than revoking these users' admin rights to the box, I can't think of a way to stop them from creating local accounts or modifying local groups.

My suggestion is to use a monitoring application to send an alert to you when one of these events occur.

PSC

Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
 
You could use a WMI script to monitor for an account creation and have it either delete the account or notify you or both.

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
I would personnaly opt for user training in this instance. Surely you can make it clear that no accounts are to be created and that any that get created will be useless after the GP refresh? As long as that is made clear, there can be no comeback.

--------------------------------------
"Insert funny comment in here!"
--------------------------------------
 
Update your acceptable use policy for third party contractors to say that they may not create local accounts. Distribute new AUP to them.
 
Enable the "legal notice" for the logon screen, which includes this information.

PSC

Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top