Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Prevent users from joining machines to workgroups

Status
Not open for further replies.

JBorecky

IS-IT--Management
Mar 16, 2002
55
US
I am the admin of a 2003 Domain. I have several users that need local admin rights on the box. <---(Developers go figure). These users keep removing themselves from the domain.(Grrr) Is there a Group Policy setting I can set to prevent them from doing this? Or a reg key I can change the permissions on? I know that I can change their membership to Power Users instead. But this would not be politically correct. And I would lose that battle. It seems to me that this is a logical setting but I can't find it anywhere in the GPO Settings. I also thought about a policy hash restriction against netdom. But am unsure which utility to restrict to include the GUI. Thanks in advance for any suggestions or answers.
 
You could create a policy for the developers and block the running of Netdom simply by name. Since it is a MS signed utility, even if they rename the EXE the GPO would still block it.

I hope you find this post helpful.

Regards,

Mark
 
You could also block their access to Control Panel System Applet but they may screem about that.

I hope you find this post helpful.

Regards,

Mark
 
But does the GUI under system properties use netdom also?
 
No that is why I was recommending you block the applet in addition to netdom.

I hope you find this post helpful.

Regards,

Mark
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top