Prevent Changing IP Address from local admin
hello i am an administrator for a small company my clients joined to an active directory domain they have administrative right (local administrators ) in their computer, because they use visual studio and they want to deploy application that need administrative right i want to prevent them to change their ip address i want to give this right only to domain admin groups in my domain what should i do? thanx and Best Regards
October 21st, 2009 12:31am
You can't prevent anything from local admin. You need to change your developers rights from local admins to users.[http://www.sysadmins.lv]
As always enjoy the automation of tools
within the Windows-based, .NET aware,
WPF accessible, multi-processes on the same IP / Port usage, admin's automation tool, powershell.exe! Flowering Weeds
Free Windows Admin Tool Kit Click here and download it now
October 21st, 2009 10:15am
after a long time, I found a way to prevent Local admin (in active directory domain) to change their IP address
we should adjust some policy in active directory
User Configuration
Administrative Templates\Network\Network Connection
3 Policy should change here
Now, I'm very tired and neeeeeeeeeeed sleep
If you can't find that 3 policy, you should comment for me :D
Boroumandan
Best Regards
November 10th, 2010 8:26pm
do you think that local administrator cannot bypass this setting? Local administrator can override any domain policy on the computer.http://en-us.sysadmins.lv
Free Windows Admin Tool Kit Click here and download it now
November 11th, 2010 9:40am
Hi Boroumandan
can you please explain to us how you succeed to prevent local administrator to change their Ip Adress.
i rtyed with all GPO in User Configuration
Administrative Templates\Network\Network Connection but no result.
Thanks a lot
May 5th, 2011 6:14am
Guys,
First of all, what OS version are you talking about? In case of Win 7, policies for Network Connections DO NOT work for local Admins (http://sourcedaddy.com/windows-7/managing-connections-using-group-policy.html)
In case of pre-Vista OS, you should enable policy "Enable Windows 2000 Network Connections settings for Administrators" to make policies applicable for local Admins
Cheers,
Andriy
Free Windows Admin Tool Kit Click here and download it now
May 30th, 2011 5:33am
Guys,
First of all, what OS version are you talking about? In case of Win 7, policies for Network Connections DO NOT work for local Admins (http://sourcedaddy.com/windows-7/managing-connections-using-group-policy.html)
In case of pre-Vista OS, you should enable policy "Enable Windows 2000 Network Connections settings for Administrators" to make policies applicable for local Admins
Cheers,
Andriy
this is not a working solution since local administrator can discard domain policies and rewrite them by his/her custom policy settings.My weblog: http://en-us.sysadmins.lv
PowerShell PKI Module: http://pspki.codeplex.com
May 30th, 2011 5:59am