fiza Posted February 2, 2017 Posted February 2, 2017 There is a setting in Group Policy at our Primary School which I don't understand. We didn't set it up but have taken over support. Can anyone tell me what the following setting would do? Its the second one (order: 2).
smithson83 Posted February 2, 2017 Posted February 2, 2017 I could be wrong, but it looks like its adding "Domain Users" to the Local Admin 1
ITGURU Posted February 2, 2017 Posted February 2, 2017 There is a setting in Group Policy at our Primary School which I don't understand. We didn't set it up but have taken over support. Can anyone tell me what the following setting would do? Its the second one (order: 2). Order 2 is a policy setting which allows you to add users as being part of the local Administrators Group. [ATTACH=CONFIG]41211[/ATTACH] I'm hoping that AZT3122048B is not your domain name otherwise this would imply that all Domain Users are local administrators on the PC! 1
jamesreedersmith Posted February 2, 2017 Posted February 2, 2017 Yes adds domain users to local administrators group. 1
3s-gtech Posted February 2, 2017 Posted February 2, 2017 That appears to be the case. As it's a local setting, just disabling the setting won't fix that. You'll need to set a policy which removes domain users from the local admins group (but doesn't remove the domain admin, unless the domain admins group is then added to local admins instead). 1
fiza Posted February 2, 2017 Author Posted February 2, 2017 That appears to be the case. As it's a local setting, just disabling the setting won't fix that. You'll need to set a policy which removes domain users from the local admins group (but doesn't remove the domain admin, unless the domain admins group is then added to local admins instead). Why would anyone set a policy like that??? Would I be able to change the policy so that the action is "remove from this group" or is it better to disable the policy and add a new one to remove domain users?
gaz350b Posted February 2, 2017 Posted February 2, 2017 imo get a maintenance plan in place to deploy a new os image deployed as you can no longer trust any of the current machines in your network. 1
TwistedHelixis Posted February 2, 2017 Posted February 2, 2017 Sorry to crash - but does that policy do the same as restricted groups? Our primary has staff group added to local admins using restricted groups, is it the same????
Rob_D Posted February 2, 2017 Posted February 2, 2017 It's worth noting that we have several pieces of software (including a SIMS plugin) that don't work unless the users are members of the local admin group. Something to look out for.
3s-gtech Posted February 2, 2017 Posted February 2, 2017 Why would anyone set a policy like that??? Would I be able to change the policy so that the action is "remove from this group" or is it better to disable the policy and add a new one to remove domain users? Because "SUPER PAINT 95 EDITION" was required by ALL staff and only worked if they were full admins. Or something like that. I'd create a new policy with the remove settings, un-link this policy then test. Once you're sure it works as you want, then roll it out. If you get it wrong you may end up disabling anything that needs access for services to run, like AV, SIMS updates etc. Make sure it's well targeted and that any accounts in Domain Users that do need to be in this group get placed back into it.
synaesthesia Posted February 2, 2017 Posted February 2, 2017 It's worth noting that we have several pieces of software (including a SIMS plugin) that don't work unless the users are members of the local admin group. Something to look out for. Doesn't mean much - I would still take immediate action to remove the policy and deal with the software as appropriate. If something must absolutely have local admin rights there needs to be a bloody good reason for it otherwise it's not fit for purpose. 1
fiza Posted February 2, 2017 Author Posted February 2, 2017 Because "SUPER PAINT 95 EDITION" was required by ALL staff and only worked if they were full admins. Or something like that. I'd create a new policy with the remove settings, un-link this policy then test. Once you're sure it works as you want, then roll it out. If you get it wrong you may end up disabling anything that needs access for services to run, like AV, SIMS updates etc. Make sure it's well targeted and that any accounts in Domain Users that do need to be in this group get placed back into it. The AV is Sophos Cloud and SIMS updates are done via SOLUS3 neither of which need users to have local admin rights. Will give it a go and wait for the inevitable phone call to say that "SUPER PAINT 95 EDITION" has stopped working!
3s-gtech Posted February 2, 2017 Posted February 2, 2017 You blocker. Buy yeah, crack on. It'll be worth doing some full scans of all machines if possible though - who know what the teachers may have been installing. Get the imaging suite polished and ready to roll too! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now