Warning message / dialog, system, machine before removing from dom

G

Guest

How do I make a warning message or dialog pop-up "before" someone removes
their system from the domain right before they select "Workgroup" and OK?

We have remote people remove themselves from the domain, and then there is
no way for them to log back in with their correct access rights and
permissions so at least providing a warning or message to first make a local
administrator account would help.

Thank you,

D.
 
S

Shenan Stanley

DPugel said:
How do I make a warning message or dialog pop-up "before" someone
removes their system from the domain right before they select
"Workgroup" and OK?

We have remote people remove themselves from the domain, and then
there is no way for them to log back in with their correct access
rights and permissions so at least providing a warning or message
to first make a local administrator account would help.


Please do not multi-post... Cross post if you think it is legitimate in more
than one place.

And your solution is to not give the users permissions to remove the machine
from the domain and have them logon locally.
If they must have installation rights - give them a different account -
local - to use to do this with express instructions that that accouint is to
be used for nothing but installations.

Otherwise - you are out of luck - you are asking to re-write windows code
and there are multiple ways to remove a machine from a domain anyway.
 
G

Guest

Shenan,

In Group Policy, is there a way to remove people's rights so they cannot
remove themselves from the domain?

Thanks,

D.
 
S

Shenan Stanley

DPugel said:
How do I make a warning message or dialog pop-up "before" someone
removes their system from the domain right before they select
"Workgroup" and OK?

We have remote people remove themselves from the domain, and then
there is no way for them to log back in with their correct access
rights and permissions so at least providing a warning or message
to first make a local administrator account would help.

Shenan said:
Please do not multi-post... Cross post if you think it is
legitimate in more than one place.

And your solution is to not give the users permissions to remove
the machine from the domain and have them logon locally.
If they must have installation rights - give them a different
account - local - to use to do this with express instructions that
that account is to be used for nothing but installations.

Otherwise - you are out of luck - you are asking to re-write
windows code and there are multiple ways to remove a machine from
a domain anyway.
In Group Policy, is there a way to remove people's rights so they
cannot remove themselves from the domain?


In your other post, you stated they are already deployed - so do they even
connect to the domain, ever?
And other than changing their rights to limited users - no...

Why? Because they do not need access to the domain at all to remove
themselves from it. They only need administrative rights on the machine.
When it asks for a username/password to remove the machine from the domain,
they could leave those fields blank and they would still be successful.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top