Is there a way to prohibit users from adding their WS to a workgroup?

D

docsneid

Most of our users are mobile users using cached credintials while they
are not connected to the network. (No local User Account) They are not
able to re-join the machine remotely to the AD if they accidently
removed it and joined the machine to a workgroup.
Is there a policy which can be set to prohibit to join a Workgroup
once a machine is setup in AD? I know about the policy "Add
workstation to domain" but couln't find something similar for a
workgroup. Or is this setting also able to handle this?
 
L

Lanwench [MVP - Exchange]

Don't give them local admin rights on their laptops, and then they can't do
anything at all like this.
 
D

docsneid

I know, but this wasn't the question. The problem is that there are
several reasons for giving them Admin rights. There is no other way.
 
T

Torgeir Bakken (MVP)

docsneid said:
I know, but this wasn't the question. The problem is that there are
several reasons for giving them Admin rights. There is no other way.

Then your only option is to tell them not to do it.
 
L

Lanwench [MVP - Exchange]

They can still do it. What's the reason they need local admin rights? And
have you given every laptop user a stern talking-to about what they are and
are not permitted to do on their laptops? If they need admin rights,
absolutely, this is not a technical issue, it's a company policy one.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top