UAC Police

G

Guest

hi.

I configure The policies "UAC: Run all administrator in Admin Approval Mode"
Enable in a Domain controler.
HOW COULD I CONFIGURE A LOCAL ADMINISTRATOR TO AVOID IT CHANGE THE USER
ACCOUNT CONTROL (UAC)?

ANY RECOMMENDATION?
 
G

Guest

Not sure what you mean by configuring UAC on the DC, considering that UAC is
only available in Vista as of now.

However, it seems your question is "how do I keep local administrators from
circumventing policies set down by domain admins?"

The answer to that question is "you can't." Local administrators are gods
iwthin the realm of the computer they administer. You cannot prevent them
from doing anything.
 
G

Guest

jesper Thanks for you answer.

I want configure the next scenary:
AD - Turn ON UAC on all client's. (Run all administrators in Admin
Approval Mode: Enable )
AD - Local administrator's elevate privileges prompt for consent
(Behavior of the elevation prompt for administrators in Admin Approval Mode:
Prompt for consent )
AD - standard user elevate privileges prompt for credentials. (Behavior
of the elevation prompt for standard users: Prompt for credentials )

AND COULD NO TURN OFF BY UNCHECK BOX "Use User Account Control (UAC) to help
protect your computer"
 
G

Guest

You cannot prevent a local admin from disabling UAC, or modifying how it
works. If you want to prevent people from doing so they must not be local
admins.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top