Jump to content

Recommended Posts

Posted

Hi All,

 

we're doing a project to move our workstations off of RM and to vanilla Windows 10.

 

When we started imaging it was fine as i could image a machine using MDT (windows 1703 was the ISO. and then if a user required local admin access i simply added them to the biult in administrators group and all was well.

 

I've updated the iso to windows 10 v1809 a few weeks back and the other day went to add a user as a local admin, we restarted the worksation and i had the user login but they were still not a local admin.

 

In an rm network and cc4 imaged pc you would normally add the user in the management console to the pc a privileged user and restart the pc however the vanilla windows way of adding a local admin seemed to work on a v1703 windows vanilla laptop the other day.

 

does anyone know what this might be?

 

i would just use 1703 however it has that ridiculour problem where users logins stall half way through with a black screen. this is why we moved to the 1809 version but have obviously now come up against this problem with adding local admin rights. I've have found that by removing the Staff User Type gpo from the domain user it gives them a little more access however in 1703 there was no need to remove a gpo etc.

 

any help greatly appreciated.

Posted
Can I ask why you need to give users local admin rights? I see no need to give users this level of access. If staff want software installed we vet it then install it if it’s okay.
Posted
Can I ask what software? I don’t know of any educational software that requires admin rights to run. Handing out even local admin rights to users is too much of a risk.
Posted
Same - I haven’t needed to do this, for any software we use, in 13 years and across all the versions of Windows in that time. There’s normally a workaround, and I’d strongly suggest concentrating on that. A compromised user account that has this level of privilege could destroy your network.
  • Thanks 1
Posted (edited)
If you have a gpo that puts users into the administrator group this will also overwrite the local admin group on gpo refresh Edited by markwilfan
Posted
If you have a gpo that puts users into the administrator group this will also overwrite the local admin group on gpo refresh

 

Not necessarily. You would have to configure the GPO to do this.

Posted
I do it under Preferences which does not remove the users unless actually specified to do so
Ah fair enough. Didn't know you could do that. I prefer the replace just in case something manages to add itself

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...