Jump to content

Recommended Posts

Posted

There is a setting in Group Policy at our Primary School which I don't understand. We didn't set it up but have taken over support.

 

Can anyone tell me what the following setting would do? Its the second one (order: 2).

 

adminaccountquery.png

Posted
There is a setting in Group Policy at our Primary School which I don't understand. We didn't set it up but have taken over support.

 

Can anyone tell me what the following setting would do? Its the second one (order: 2).

 

Order 2 is a policy setting which allows you to add users as being part of the local Administrators Group.

 

[ATTACH=CONFIG]41211[/ATTACH]

 

I'm hoping that AZT3122048B is not your domain name otherwise this would imply that all Domain Users are local administrators on the PC!

  • Thanks 1
Posted
That appears to be the case. As it's a local setting, just disabling the setting won't fix that. You'll need to set a policy which removes domain users from the local admins group (but doesn't remove the domain admin, unless the domain admins group is then added to local admins instead).
  • Thanks 1
Posted
That appears to be the case. As it's a local setting, just disabling the setting won't fix that. You'll need to set a policy which removes domain users from the local admins group (but doesn't remove the domain admin, unless the domain admins group is then added to local admins instead).

 

Why would anyone set a policy like that???

 

Would I be able to change the policy so that the action is "remove from this group" or is it better to disable the policy and add a new one to remove domain users?

Posted
imo get a maintenance plan in place to deploy a new os image deployed as you can no longer trust any of the current machines in your network.
  • Thanks 1
Posted

It's worth noting that we have several pieces of software (including a SIMS plugin) that don't work unless the users are members of the local admin group.

Something to look out for.

Posted
Why would anyone set a policy like that???

 

Would I be able to change the policy so that the action is "remove from this group" or is it better to disable the policy and add a new one to remove domain users?

 

Because "SUPER PAINT 95 EDITION" was required by ALL staff and only worked if they were full admins. Or something like that. I'd create a new policy with the remove settings, un-link this policy then test. Once you're sure it works as you want, then roll it out. If you get it wrong you may end up disabling anything that needs access for services to run, like AV, SIMS updates etc. Make sure it's well targeted and that any accounts in Domain Users that do need to be in this group get placed back into it.

Posted
It's worth noting that we have several pieces of software (including a SIMS plugin) that don't work unless the users are members of the local admin group.

Something to look out for.

 

Doesn't mean much - I would still take immediate action to remove the policy and deal with the software as appropriate. If something must absolutely have local admin rights there needs to be a bloody good reason for it otherwise it's not fit for purpose.

  • Thanks 1
Posted
Because "SUPER PAINT 95 EDITION" was required by ALL staff and only worked if they were full admins. Or something like that. I'd create a new policy with the remove settings, un-link this policy then test. Once you're sure it works as you want, then roll it out. If you get it wrong you may end up disabling anything that needs access for services to run, like AV, SIMS updates etc. Make sure it's well targeted and that any accounts in Domain Users that do need to be in this group get placed back into it.

 

The AV is Sophos Cloud and SIMS updates are done via SOLUS3 neither of which need users to have local admin rights. Will give it a go and wait for the inevitable phone call to say that "SUPER PAINT 95 EDITION" has stopped working!

Posted

You blocker.

 

Buy yeah, crack on. It'll be worth doing some full scans of all machines if possible though - who know what the teachers may have been installing. Get the imaging suite polished and ready to roll too!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...