Windows XP Community - XPHeads



Disable logon to XP without disabling or locking account?

microsoft.public.windowsxp.security_admin


Reply
  #1 (permalink)  
Old 03-12-2008, 11:04 PM
hemlockz
 
Posts: n/a
Disable logon to XP without disabling or locking account?
We have a couple domain accounts that are members of the local
Administrators group on all our workstations. (Our domain users are
Power Users.) We use these accounts to log in and install programs
and things that Power Users cannot. A while ago one of the IT created
another account and added it to the group with the intent of using the
account for Run As... installation scripts and things of that nature.
Pretty soon a couple of domain users have read the batch files and
taken the password for that account and are now using it to log on to
their workstations and install software. They only call IT after they
have ruined their registry or downloaded a virus. The Run As...
account has been very helpful and a huge time saver but opened up this
security hole. It would not be so much of a problem if we could
restrict log on from the account but still use it to "Run As..."
Unfortunately if I modify the Log On To... under the account
properties in Active Directory the Run As... will not work unless the
the account is also allowed to log on. Is there anything we can do to
prevent the account from logging on to Windows XP, but still be able
to Run As...? Thanks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 03-13-2008, 07:08 PM
Lanwench [MVP - Exchange]
 
Posts: n/a
Re: Disable logon to XP without disabling or locking account?
hemlockz <ian.m.cameron@gmail.com> wrote:
> We have a couple domain accounts that are members of the local
> Administrators group on all our workstations. (Our domain users are
> Power Users.)


Note that Power Users is pretty nearly Administrators in XP - I'd rethink
this. They really ought to just be users.

> We use these accounts to log in and install programs
> and things that Power Users cannot. A while ago one of the IT created
> another account and added it to the group with the intent of using the
> account for Run As... installation scripts and things of that nature.
> Pretty soon a couple of domain users have read the batch files and
> taken the password for that account and are now using it to log on to
> their workstations and install software. They only call IT after they
> have ruined their registry or downloaded a virus. The Run As...
> account has been very helpful and a huge time saver but opened up this
> security hole. It would not be so much of a problem if we could
> restrict log on from the account but still use it to "Run As..."
> Unfortunately if I modify the Log On To... under the account
> properties in Active Directory the Run As... will not work unless the
> the account is also allowed to log on. Is there anything we can do to
> prevent the account from logging on to Windows XP, but still be able
> to Run As...? Thanks.


The short answer is no. . I would suggest you pull back from trying address
the symptom, in favor of curing the problem, which is that you've got
passwords in clear text. Change the password immediately, and never embed
passwords in clear text /
in batch files like that.

There are many runas alternatives - see http://www.wingnutsoftware.com/ for
an option.








Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:08 PM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74