Jump to content

Recommended Posts

Posted

Hi all. We support around 50 sites, we run Windows 7 and some Windows 10 with server 2008-2016. The usual types of software like Office 2010-2016 and Clevertouch Lynx, Smartboard, SIMS, etc. We also use Centrastageto deploy apps and also GPOs! We like to keep Adobe Acrobat, Java, Flash etc up to date. Normally we use Ninite (free) or manually run it.

 

We use mandatory profiles

 

Its now been decided to revoke local admin rights to the machines. We currently make domain users a member of the local administrators group, I have done some testing and found:

Lynx does not take an update using the self updater,

Acrobat won't update, neither does Java.

Not sure about SIMS, but I gather Solus will run ok? Need to check this with our sims team.

 

Has anyone been through this? Any fixes or tips?

 

I have logged a case with Clevertouch, googling has not turned up anything of use.

Posted
Hi all. We support around 50 sites, we run Windows 7 and some Windows 10 with server 2008-2016. The usual types of software like Office 2010-2016 and Clevertouch Lynx, Smartboard, SIMS, etc. We also use Centrastageto deploy apps and also GPOs! We like to keep Adobe Acrobat, Java, Flash etc up to date. Normally we use Ninite (free) or manually run it.

 

We use mandatory profiles

 

Its now been decided to revoke local admin rights to the machines. We currently make domain users a member of the local administrators group, I have done some testing and found:

Lynx does not take an update using the self updater,

Acrobat won't update, neither does Java.

Not sure about SIMS, but I gather Solus will run ok? Need to check this with our sims team.

 

Has anyone been through this? Any fixes or tips?

 

I have logged a case with Clevertouch, googling has not turned up anything of use.

 

As a lot of programs won't update under a user context without admin rights, most of us deploy software centrally from via GPOs (via Software Deployment and/or Startup Scripts), or use tools such as SCCM or WPKG-gp for deploying software. When we find out an update is needed we configure a new package to deploy.

Posted
SIMS itself should be fine, SOLUS will manage the updates as this runs as a service with sufficient permissions. FMS is more of an issue (if you do use it). There are some considerable changes that need to take place for this to work correctly. If you do go with something like SCCM or PDQDeploy then that should be easy to do though.
Posted
Hi Mate, I did this a few years ago to mitigate the risk of malicious code\software being executed locally. In short it initially cuased some headaches but from a patching perspective we push 3rd party software to out updates which essentially runs in the context of a local administrator.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...