Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Domain Users/Restrict to User Access Only.

Reply
Thread Tools Display Modes

Domain Users/Restrict to User Access Only.

 
 
Andrew Staley
Guest
Posts: n/a

 
      03-11-2009
We're currently running a Server 2003 and looking to tighten up our
security. One thing that I know has happened in the past is that certain
PC's have had accounts created for domain users and they've been left with
full Admin privlages.

Is there a simple way, via Group Policy perhaps that I can knock all these
accounts back down to User Only access? If not my only alternative is to go
around some 200 machines and change them manually.

Thanks in advance, Andrew.

 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-11-2009
Hello Andrew,

Assuming that you talk about user accounts being in the local administrators
group you can use Restricted groups to remove/replace them with the needed
accounts:
http://www.frickelsoft.net/blog/?p=13

Keep attention on the "Members of this group" and "This group is a member
of", to find your way.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> We're currently running a Server 2003 and looking to tighten up our
> security. One thing that I know has happened in the past is that
> certain PC's have had accounts created for domain users and they've
> been left with full Admin privlages.
>
> Is there a simple way, via Group Policy perhaps that I can knock all
> these accounts back down to User Only access? If not my only
> alternative is to go around some 200 machines and change them
> manually.
>
> Thanks in advance, Andrew.
>



 
Reply With Quote
 
Andrew Staley
Guest
Posts: n/a

 
      03-11-2009

Thanks for the reply. I've read through the guide, but must be missing
something.

I've created a GPO that is applying. I'm using "Members of the group" to
leave only Administrator in the admin group and for test purposes I'm
setting my own account to user. My account started as admin, GPO was
applied on restart and my domain account show's as user. But I can still
modify the system and install apps as if I'm a full administrator??

Any pointers on where I may have gone wrong?

Thanks, Andrew

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news: .com...
> Hello Andrew,
>
> Assuming that you talk about user accounts being in the local
> administrators group you can use Restricted groups to remove/replace them
> with the needed accounts:
> http://www.frickelsoft.net/blog/?p=13
>
> Keep attention on the "Members of this group" and "This group is a member
> of", to find your way.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> We're currently running a Server 2003 and looking to tighten up our
>> security. One thing that I know has happened in the past is that
>> certain PC's have had accounts created for domain users and they've
>> been left with full Admin privlages.
>>
>> Is there a simple way, via Group Policy perhaps that I can knock all
>> these accounts back down to User Only access? If not my only
>> alternative is to go around some 200 machines and change them
>> manually.
>>
>> Thanks in advance, Andrew.
>>

>
>


 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-11-2009
Hello Andrew,

Did you check the Administrators group in Local users and groups on the client
machine? What members are in that group?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Thanks for the reply. I've read through the guide, but must be
> missing something.
>
> I've created a GPO that is applying. I'm using "Members of the group"
> to leave only Administrator in the admin group and for test purposes
> I'm setting my own account to user. My account started as admin, GPO
> was applied on restart and my domain account show's as user. But I
> can still modify the system and install apps as if I'm a full
> administrator??
>
> Any pointers on where I may have gone wrong?
>
> Thanks, Andrew
>
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
> news: .com...
>
>> Hello Andrew,
>>
>> Assuming that you talk about user accounts being in the local
>> administrators group you can use Restricted groups to remove/replace
>> them
>> with the needed accounts:
>> http://www.frickelsoft.net/blog/?p=13
>> Keep attention on the "Members of this group" and "This group is a
>> member of", to find your way.
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> We're currently running a Server 2003 and looking to tighten up our
>>> security. One thing that I know has happened in the past is that
>>> certain PC's have had accounts created for domain users and they've
>>> been left with full Admin privlages.
>>>
>>> Is there a simple way, via Group Policy perhaps that I can knock all
>>> these accounts back down to User Only access? If not my only
>>> alternative is to go around some 200 machines and change them
>>> manually.
>>>
>>> Thanks in advance, Andrew.
>>>



 
Reply With Quote
 
Marcin
Guest
Posts: n/a

 
      03-11-2009
Andrew,
review Security Options, User Right Assignments, and custom permissions
applicable to the target computer...

hth
Marcin

"Andrew Staley" <no-> wrote in message
news:9D314CBD-D581-4D22-B4E8-...
>
> Thanks for the reply. I've read through the guide, but must be missing
> something.
>
> I've created a GPO that is applying. I'm using "Members of the group" to
> leave only Administrator in the admin group and for test purposes I'm
> setting my own account to user. My account started as admin, GPO was
> applied on restart and my domain account show's as user. But I can still
> modify the system and install apps as if I'm a full administrator??
>
> Any pointers on where I may have gone wrong?
>
> Thanks, Andrew
>
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
> news: .com...
>> Hello Andrew,
>>
>> Assuming that you talk about user accounts being in the local
>> administrators group you can use Restricted groups to remove/replace them
>> with the needed accounts:
>> http://www.frickelsoft.net/blog/?p=13
>>
>> Keep attention on the "Members of this group" and "This group is a member
>> of", to find your way.
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>
>>> We're currently running a Server 2003 and looking to tighten up our
>>> security. One thing that I know has happened in the past is that
>>> certain PC's have had accounts created for domain users and they've
>>> been left with full Admin privlages.
>>>
>>> Is there a simple way, via Group Policy perhaps that I can knock all
>>> these accounts back down to User Only access? If not my only
>>> alternative is to go around some 200 machines and change them
>>> manually.
>>>
>>> Thanks in advance, Andrew.
>>>

>>
>>

>



 
Reply With Quote
 
Andrew Staley
Guest
Posts: n/a

 
      03-12-2009
I checked the Security Options and all these are undefined.

I've gone into Computer Management and checked Administrator, my username
isn't shown there only Administrator. I've checked User and my username is
shown there.

I've then run "gpresult" and it show's that the policy has applied. Same
with the GPResult Wizard on the DC.

Within the GPO I've created two group names, Administrators, which contains
under "Member of the Group" DOMAIN_NAME\Administrator. And Users also under
the same sction containing DOMAIN_NAME\My Username.

On the PC Administrators/Users show exactly as defined above. No local
accounts, just those I've defined above. Could this be part of the problem?

AStaley.

"Marcin" <> wrote in message
news:...
> Andrew,
> review Security Options, User Right Assignments, and custom permissions
> applicable to the target computer...
>
> hth
> Marcin
>
> "Andrew Staley" <no-> wrote in message
> news:9D314CBD-D581-4D22-B4E8-...
>>
>> Thanks for the reply. I've read through the guide, but must be missing
>> something.
>>
>> I've created a GPO that is applying. I'm using "Members of the group" to
>> leave only Administrator in the admin group and for test purposes I'm
>> setting my own account to user. My account started as admin, GPO was
>> applied on restart and my domain account show's as user. But I can still
>> modify the system and install apps as if I'm a full administrator??
>>
>> Any pointers on where I may have gone wrong?
>>
>> Thanks, Andrew
>>
>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
>> news: .com...
>>> Hello Andrew,
>>>
>>> Assuming that you talk about user accounts being in the local
>>> administrators group you can use Restricted groups to remove/replace
>>> them with the needed accounts:
>>> http://www.frickelsoft.net/blog/?p=13
>>>
>>> Keep attention on the "Members of this group" and "This group is a
>>> member of", to find your way.
>>>
>>> Best regards
>>>
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>
>>>> We're currently running a Server 2003 and looking to tighten up our
>>>> security. One thing that I know has happened in the past is that
>>>> certain PC's have had accounts created for domain users and they've
>>>> been left with full Admin privlages.
>>>>
>>>> Is there a simple way, via Group Policy perhaps that I can knock all
>>>> these accounts back down to User Only access? If not my only
>>>> alternative is to go around some 200 machines and change them
>>>> manually.
>>>>
>>>> Thanks in advance, Andrew.
>>>>
>>>
>>>

>>

>
>


 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-12-2009
Hello Andrew,

Use "Members of this group" and add there the accounts that should be local
admin, that's all. Other existing local admins will be removed with this
setting.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I checked the Security Options and all these are undefined.
>
> I've gone into Computer Management and checked Administrator, my
> username isn't shown there only Administrator. I've checked User and
> my username is shown there.
>
> I've then run "gpresult" and it show's that the policy has applied.
> Same with the GPResult Wizard on the DC.
>
> Within the GPO I've created two group names, Administrators, which
> contains under "Member of the Group" DOMAIN_NAME\Administrator. And
> Users also under the same sction containing DOMAIN_NAME\My Username.
>
> On the PC Administrators/Users show exactly as defined above. No
> local accounts, just those I've defined above. Could this be part of
> the problem?
>
> AStaley.
>
> "Marcin" <> wrote in message
> news:...
>
>> Andrew,
>> review Security Options, User Right Assignments, and custom
>> permissions
>> applicable to the target computer...
>> hth
>> Marcin
>> "Andrew Staley" <no-> wrote in message
>> news:9D314CBD-D581-4D22-B4E8-...
>>
>>> Thanks for the reply. I've read through the guide, but must be
>>> missing something.
>>>
>>> I've created a GPO that is applying. I'm using "Members of the
>>> group" to leave only Administrator in the admin group and for test
>>> purposes I'm setting my own account to user. My account started as
>>> admin, GPO was applied on restart and my domain account show's as
>>> user. But I can still modify the system and install apps as if I'm
>>> a full administrator??
>>>
>>> Any pointers on where I may have gone wrong?
>>>
>>> Thanks, Andrew
>>>
>>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
>>> news: .com...
>>>
>>>> Hello Andrew,
>>>>
>>>> Assuming that you talk about user accounts being in the local
>>>> administrators group you can use Restricted groups to
>>>> remove/replace
>>>> them with the needed accounts:
>>>> http://www.frickelsoft.net/blog/?p=13
>>>> Keep attention on the "Members of this group" and "This group is a
>>>> member of", to find your way.
>>>>
>>>> Best regards
>>>>
>>>> Meinolf Weber
>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>> and
>>>> confers no rights.
>>>> ** Please do NOT email, only reply to Newsgroups
>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>> We're currently running a Server 2003 and looking to tighten up
>>>>> our security. One thing that I know has happened in the past is
>>>>> that certain PC's have had accounts created for domain users and
>>>>> they've been left with full Admin privlages.
>>>>>
>>>>> Is there a simple way, via Group Policy perhaps that I can knock
>>>>> all these accounts back down to User Only access? If not my only
>>>>> alternative is to go around some 200 machines and change them
>>>>> manually.
>>>>>
>>>>> Thanks in advance, Andrew.
>>>>>



 
Reply With Quote
 
Andrew Staley
Guest
Posts: n/a

 
      03-13-2009
That worked perfectly. Thank you for you help.

Andrew.

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news: .com...
> Hello Andrew,
>
> Use "Members of this group" and add there the accounts that should be
> local admin, that's all. Other existing local admins will be removed with
> this setting.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> I checked the Security Options and all these are undefined.
>>
>> I've gone into Computer Management and checked Administrator, my
>> username isn't shown there only Administrator. I've checked User and
>> my username is shown there.
>>
>> I've then run "gpresult" and it show's that the policy has applied.
>> Same with the GPResult Wizard on the DC.
>>
>> Within the GPO I've created two group names, Administrators, which
>> contains under "Member of the Group" DOMAIN_NAME\Administrator. And
>> Users also under the same sction containing DOMAIN_NAME\My Username.
>>
>> On the PC Administrators/Users show exactly as defined above. No
>> local accounts, just those I've defined above. Could this be part of
>> the problem?
>>
>> AStaley.
>>
>> "Marcin" <> wrote in message
>> news:...
>>
>>> Andrew,
>>> review Security Options, User Right Assignments, and custom
>>> permissions
>>> applicable to the target computer...
>>> hth
>>> Marcin
>>> "Andrew Staley" <no-> wrote in message
>>> news:9D314CBD-D581-4D22-B4E8-...
>>>
>>>> Thanks for the reply. I've read through the guide, but must be
>>>> missing something.
>>>>
>>>> I've created a GPO that is applying. I'm using "Members of the
>>>> group" to leave only Administrator in the admin group and for test
>>>> purposes I'm setting my own account to user. My account started as
>>>> admin, GPO was applied on restart and my domain account show's as
>>>> user. But I can still modify the system and install apps as if I'm
>>>> a full administrator??
>>>>
>>>> Any pointers on where I may have gone wrong?
>>>>
>>>> Thanks, Andrew
>>>>
>>>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
>>>> news: .com...
>>>>
>>>>> Hello Andrew,
>>>>>
>>>>> Assuming that you talk about user accounts being in the local
>>>>> administrators group you can use Restricted groups to
>>>>> remove/replace
>>>>> them with the needed accounts:
>>>>> http://www.frickelsoft.net/blog/?p=13
>>>>> Keep attention on the "Members of this group" and "This group is a
>>>>> member of", to find your way.
>>>>>
>>>>> Best regards
>>>>>
>>>>> Meinolf Weber
>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>> and
>>>>> confers no rights.
>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>> We're currently running a Server 2003 and looking to tighten up
>>>>>> our security. One thing that I know has happened in the past is
>>>>>> that certain PC's have had accounts created for domain users and
>>>>>> they've been left with full Admin privlages.
>>>>>>
>>>>>> Is there a simple way, via Group Policy perhaps that I can knock
>>>>>> all these accounts back down to User Only access? If not my only
>>>>>> alternative is to go around some 200 machines and change them
>>>>>> manually.
>>>>>>
>>>>>> Thanks in advance, Andrew.
>>>>>>

>
>


 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-13-2009
Hello Andrew,

Nice to hear, thanks for the feedback.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> That worked perfectly. Thank you for you help.
>
> Andrew.
>
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
> news: .com...
>
>> Hello Andrew,
>>
>> Use "Members of this group" and add there the accounts that should be
>> local admin, that's all. Other existing local admins will be removed
>> with this setting.
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> I checked the Security Options and all these are undefined.
>>>
>>> I've gone into Computer Management and checked Administrator, my
>>> username isn't shown there only Administrator. I've checked User
>>> and my username is shown there.
>>>
>>> I've then run "gpresult" and it show's that the policy has applied.
>>> Same with the GPResult Wizard on the DC.
>>>
>>> Within the GPO I've created two group names, Administrators, which
>>> contains under "Member of the Group" DOMAIN_NAME\Administrator. And
>>> Users also under the same sction containing DOMAIN_NAME\My Username.
>>>
>>> On the PC Administrators/Users show exactly as defined above. No
>>> local accounts, just those I've defined above. Could this be part
>>> of the problem?
>>>
>>> AStaley.
>>>
>>> "Marcin" <> wrote in message
>>> news:...
>>>
>>>> Andrew,
>>>> review Security Options, User Right Assignments, and custom
>>>> permissions
>>>> applicable to the target computer...
>>>> hth
>>>> Marcin
>>>> "Andrew Staley" <no-> wrote in message
>>>> news:9D314CBD-D581-4D22-B4E8-...
>>>>> Thanks for the reply. I've read through the guide, but must be
>>>>> missing something.
>>>>>
>>>>> I've created a GPO that is applying. I'm using "Members of the
>>>>> group" to leave only Administrator in the admin group and for test
>>>>> purposes I'm setting my own account to user. My account started
>>>>> as admin, GPO was applied on restart and my domain account show's
>>>>> as user. But I can still modify the system and install apps as if
>>>>> I'm a full administrator??
>>>>>
>>>>> Any pointers on where I may have gone wrong?
>>>>>
>>>>> Thanks, Andrew
>>>>>
>>>>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
>>>>> news: .com...
>>>>>
>>>>>> Hello Andrew,
>>>>>>
>>>>>> Assuming that you talk about user accounts being in the local
>>>>>> administrators group you can use Restricted groups to
>>>>>> remove/replace
>>>>>> them with the needed accounts:
>>>>>> http://www.frickelsoft.net/blog/?p=13
>>>>>> Keep attention on the "Members of this group" and "This group is
>>>>>> a
>>>>>> member of", to find your way.
>>>>>> Best regards
>>>>>>
>>>>>> Meinolf Weber
>>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>>> and
>>>>>> confers no rights.
>>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>>> ** HELP us help YOU!!!
>>>>>> http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>>> We're currently running a Server 2003 and looking to tighten up
>>>>>>> our security. One thing that I know has happened in the past is
>>>>>>> that certain PC's have had accounts created for domain users and
>>>>>>> they've been left with full Admin privlages.
>>>>>>>
>>>>>>> Is there a simple way, via Group Policy perhaps that I can knock
>>>>>>> all these accounts back down to User Only access? If not my
>>>>>>> only alternative is to go around some 200 machines and change
>>>>>>> them manually.
>>>>>>>
>>>>>>> Thanks in advance, Andrew.
>>>>>>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Domain Users/Restrict to User Access Only. Andrew Staley Windows Server 8 03-13-2009 02:53 PM
RE: Restrict RWW user access to only his or her computer via Domain Gr Sean Windows Small Business Server 0 12-09-2008 05:29 PM
allow all local users but restrict certain domain users to logonlocally OM Active Directory 3 02-20-2008 07:39 PM
Restrict access to computers for all domain users during certain t WBStech Windows Server 0 01-12-2006 11:04 PM
Restrict access to domain users Restricting internet access to non-domai Server Networking 1 10-07-2005 02:07 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59