MatTheTech Posted May 26, 2019 Posted May 26, 2019 Hi All, we're doing a project to move our workstations off of RM and to vanilla Windows 10. When we started imaging it was fine as i could image a machine using MDT (windows 1703 was the ISO. and then if a user required local admin access i simply added them to the biult in administrators group and all was well. I've updated the iso to windows 10 v1809 a few weeks back and the other day went to add a user as a local admin, we restarted the worksation and i had the user login but they were still not a local admin. In an rm network and cc4 imaged pc you would normally add the user in the management console to the pc a privileged user and restart the pc however the vanilla windows way of adding a local admin seemed to work on a v1703 windows vanilla laptop the other day. does anyone know what this might be? i would just use 1703 however it has that ridiculour problem where users logins stall half way through with a black screen. this is why we moved to the 1809 version but have obviously now come up against this problem with adding local admin rights. I've have found that by removing the Staff User Type gpo from the domain user it gives them a little more access however in 1703 there was no need to remove a gpo etc. any help greatly appreciated.
thimon Posted May 26, 2019 Posted May 26, 2019 Can I ask why you need to give users local admin rights? I see no need to give users this level of access. If staff want software installed we vet it then install it if it’s okay.
MatTheTech Posted May 26, 2019 Author Posted May 26, 2019 I'm fairly new there but historically some of the software there in use will only operate fully under a local admin
thimon Posted May 26, 2019 Posted May 26, 2019 Can I ask what software? I don’t know of any educational software that requires admin rights to run. Handing out even local admin rights to users is too much of a risk.
3s-gtech Posted May 26, 2019 Posted May 26, 2019 Same - I haven’t needed to do this, for any software we use, in 13 years and across all the versions of Windows in that time. There’s normally a workaround, and I’d strongly suggest concentrating on that. A compromised user account that has this level of privilege could destroy your network. 1
strawberry Posted May 26, 2019 Posted May 26, 2019 In what way are they not a local admin? you may have GPO's blocking what you would consider admin behaviour.
markwilfan Posted May 26, 2019 Posted May 26, 2019 (edited) If you have a gpo that puts users into the administrator group this will also overwrite the local admin group on gpo refresh Edited May 26, 2019 by markwilfan
snagrat Posted May 26, 2019 Posted May 26, 2019 If you have a gpo that puts users into the administrator group this will also overwrite the local admin group on gpo refresh Not necessarily. You would have to configure the GPO to do this.
markwilfan Posted May 27, 2019 Posted May 27, 2019 Not necessarily. You would have to configure the GPO to do this.Users get replaced but groups are additive https://richardstk.com/2013/11/26/adding-domain-users-to-the-local-administrators-group-using-group-policy/
snagrat Posted May 27, 2019 Posted May 27, 2019 Users get replaced but groups are additive https://richardstk.com/2013/11/26/adding-domain-users-to-the-local-administrators-group-using-group-policy/ I do it under Preferences which does not remove the users unless actually specified to do so
markwilfan Posted May 27, 2019 Posted May 27, 2019 I do it under Preferences which does not remove the users unless actually specified to do soAh fair enough. Didn't know you could do that. I prefer the replace just in case something manages to add itself
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now