Home All Groups Group Topic Archive Search About
Author
16 Mar 2009 8:42 PM
franku
I have one user who has locked down his pc.

We about to let him go very quitely but before I want to change his local
admin password.

It seems no matter what I try he locked out the domain admin even from ads I
can not add myself as local admin or rdphis desktop

Is there anyway to take over the pc from ADS or remote so I can change the
password?

Author
16 Mar 2009 9:14 PM
kj [SBS MVP]
franku wrote:
> I have one user who has locked down his pc.
>
> We about to let him go very quitely but before I want to change his
> local admin password.
>
> It seems no matter what I try he locked out the domain admin even
> from ads I can not add myself as local admin or rdphis desktop
>
> Is there anyway to take over the pc from ADS or remote so I can
> change the password?

Use restricted groups group policy to enforce the domain admins membership
of his local administrators group.

http://technet.microsoft.com/en-us/library/cc756802.aspx


--
/kj
Author
16 Mar 2009 9:27 PM
Jorge Silva
Hi
If the machine belongs to your domain, you can enforce the Domain Admin in
his PC using GPO Restriction Group Policy. If he removes the Domain Admin
from local administrators security group, that configuration (which is the
default-The Domain Admins by default belong to the Local Administrators)
will be replaced in the next GPO refresh.

Now, there're some ways to run away from that, but if I were you I would
talk to that guy first or check his Workstation to check what's going on and
why is he locking you out from his workstation, then explain him the company
policy and why things are supposed to work has planned.

Remember that even if you change the Local Administrator's password, is very
easy to revert that action to that user that will have full control again of
his workstation. Most iimportant is to follow your company policy and
warning him about the consequences if he does not follow them.
--

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Show quoteHide quote
"franku" <fra***@discussions.microsoft.com> wrote in message
news:A62DB3A9-6521-43E2-AA76-8F8668F318B9@microsoft.com...
>I have one user who has locked down his pc.
>
> We about to let him go very quitely but before I want to change his local
> admin password.
>
> It seems no matter what I try he locked out the domain admin even from ads
> I
> can not add myself as local admin or rdphis desktop
>
> Is there anyway to take over the pc from ADS or remote so I can change the
> password?
>
>
Author
17 Mar 2009 3:51 AM
Ace Fekay [Microsoft Certified Trainer]
In news:A62DB3A9-6521-43E2-AA76-8F8668F318B9@microsoft.com,
franku <fra***@discussions.microsoft.com>, posted the following:
> I have one user who has locked down his pc.
>
> We about to let him go very quitely but before I want to change his
> local admin password.
>
> It seems no matter what I try he locked out the domain admin even
> from ads I can not add myself as local admin or rdphis desktop
>
> Is there anyway to take over the pc from ADS or remote so I can
> change the password?


Restricted groups, as already mentioned, will do the trick, provided the
machine is still a domain member.

If he removed the machine account from AD, then I would imagine to wait for
him to go home for the day, remove him from domain admins, and/or local
admins, apply restricted groups, so you have full control of the machine and
he can no longer make changes. If he complains, remind him what Jorge
mentioned: Company policy and consequences.

Maybe it's time to let him go sooner than you would have liked to?

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
ace***@mvps.RemoveThisPart.org

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.
Author
17 Mar 2009 7:34 AM
Florian Frommherz [MVP]
Howdie!

Ace Fekay [Microsoft Certified Trainer] wrote:
> If he removed the machine account from AD, then I would imagine to wait
> for him to go home for the day, remove him from domain admins, and/or
> local admins, apply restricted groups, so you have full control of the
> machine and he can no longer make changes. If he complains, remind him
> what Jorge mentioned: Company policy and consequences.
>
> Maybe it's time to let him go sooner than you would have liked to?

Yeah. Another reason why people should run as admins of their machines.
It actually doesn't ease the management pain on the machines, it
sometimes makes it harder to push a common config or enforce a valid
configuration throughout all clients. Specially when people think they
need to be gods on their machines and shut it down.

Hum... that leads me to a good idea: why not write a bill for the
machine and let the user pay for it? Since he locked it down, he might
wanna take it home and use it there, privately?

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
Author
17 Mar 2009 11:40 PM
Ace Fekay [Microsoft Certified Trainer]
In news:utIYAMtpJHA.6132@TK2MSFTNGP06.phx.gbl,
Florian Frommherz [MVP] <flor***@frickelsoft.DELETETHIS.net>, posted the
following:

<snipped>

> Hum... that leads me to a good idea: why not write a bill for the
> machine and let the user pay for it? Since he locked it down, he might
> wanna take it home and use it there, privately?
>
> Cheers,
> Florian

I agree, Florian!!!

Ace
Author
17 Mar 2009 9:50 AM
Meinolf Weber [MVP-DS]
Hello franku,

As suggested from the other, Restricted groups will do it. And also i would
remove the users the local admin rights, no need that they have them. Software
runs without being local admin, if problems exist they can be evaluated with
"Process Monitor" from sysinternals and then you can configure the needed
permissions on the folders/files or registry.

Process Monitor v2.03
http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Show quoteHide quote
> I have one user who has locked down his pc.
>
> We about to let him go very quitely but before I want to change his
> local admin password.
>
> It seems no matter what I try he locked out the domain admin even from
> ads I can not add myself as local admin or rdphis desktop
>
> Is there anyway to take over the pc from ADS or remote so I can change
> the password?
>