Group Policy for Computer

P

Paul

We are going to install an application that requires
administrative right.

Our network administrator suggests setting the computer
policy to admin-enabled group. Ask the end users to
install the software by themselves AND move it back to non-
admin policy.

Is it the correct way to roll out the software ? What is
the disadvantage of doing so ? Does it mean that everyone
logs into the workstations have administrative privilege ?

Thanks
 
S

Steven L Umbach

If it requires that an admin just install the software and not for using the
software you should avoid making users local administrators if at all
possible. If the application is an .msi package or can be transformed into a
..msi package it can be assigned to computers or user using Group Policy and
then the users will not need to be local administrators. Being a local
administrator does not give any a user any special powers in the domain but
it does increase the chance of users misconfiguring their computers and
installing unauthorized software for the period that they are local
administrators. You know your users better than I do and that may be a risk
you are willing to take but see if using Group Policy to install software is
a possibility first. The link below may help. --- Steve

http://www.microsoft.com/resources/...dowsserv/2003/standard/proddocs/en-us/ADE.asp
http://tinyurl.com/3qny4 -- same link as above in case of wrap.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top