R
R
Ruslan2015-05-22 08:18:18
System administration
Ruslan, 2015-05-22 08:18:18

How to protect workstation from admin password reset in windows?

Good afternoon.
Actually a subject. Let's say there are branches in which there may be advanced users and I would like some kind of protection against resetting the administrator password.
Methods like "seal, close USB / drives", etc. unsuitable. I would like to solve the issue properly.
Thanks

Answer the question

In order to leave comments, you need to log in

8 answer(s)
C
cssman, 2015-05-22
@flay_er

APMDZ stick into each system unit

A
Artem, 2015-05-22
@ulkoart

Domain. In the local administrators group, leave only the administrator from the domain.

A
Artem @Jump, 2015-05-22
Tag

Exclude loading from the left media, and the ability to access the HDD.
That is, the password for the BIOS, and the actual sealing of the case.
The alternative is encryption.

M
mace-ftl, 2015-05-22
@mace-ftl

Encrypt disk is the main method

O
other_letter, 2015-05-22
@other_letter

If there is no competent specialist on site who will follow, it's all empty.
But how I did:
1. Password or BIOS
2. Prohibition to boot from something else
3. On the body - a lock and a seal
4. An unresolved problem - the hotkey on the boot option sometimes does not turn off
You might think about putting stations into terminal mode , you can already see it.

S
Sergey, 2015-05-22
@bk0011m

The minimum alignment (as written above):
1. Disabling booting from any media other than HDD
2. BIOS password + sealing cases.
3. Disable local admin. You can turn it on later from any boot disk. You know the BIOS password
4. Administrative measures. That is, caught red-handed to punish with deprivation of bonuses or other bonuses. IMHO the most efficient method.
But first you need to convince management of the need for these measures. Otherwise, problems may arise, you already have.
I wouldn't encrypt. This is a very big hemorrhoid. Fuss a lot, there is a risk of data loss. Additional load on workstations, etc.

P
Puma Thailand, 2015-05-24
@opium

Usually I put a password on the BIOS and allow it to boot only from the disk.

Y
younghacker, 2015-05-29
@younghacker

If you have physical access to a computer, which you don't, there will be a craftsman.
Install disk-free linux terminals, and drive users to the terminal server and that's the end of it.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question