Run as administrator / disable logon locally

Siberiantiger

New member
Local time
5:14 PM
Messages
2
Hi!

Is there a way to prevent users from logging on locally with a spesific local user (first PC login) but still be able to Run as local user after logged on to the PC with a AD user?
 

My Computer My Computer

At a glance

Windows 7 Enterprise 64biti58GB
Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Enterprise 64bit
CPU
i5
Memory
8GB
Hard Drives
180 GB Intel SSD
To login with Run as requires the ability for one to login into that account locally. You cannot have your cake and eat it as well.
 

My Computer My Computer

At a glance

Windows 10 Pro (x64)Intel Core i7-3930K (3.2GHz - 4.5GHz)4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)Nvidia Geforce GTX 690
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Thanks for your reply. Our case is users that have an active directory user that is not local administrator. But they do have access to a local administrator user on the computer that they can use to run or install certain software that needs admin rights, but we do not want them to only login as the local administrator all times, just when they really need it. So f.eks preventing them from reaching printeres or fileshares when logged on as a local user would be nice. Is this possible or is there any better ideas?
 

My Computer My Computer

At a glance

Windows 7 Enterprise 64biti58GB
Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Enterprise 64bit
CPU
i5
Memory
8GB
Hard Drives
180 GB Intel SSD
Hi Siberiantiger,
same thing here.

I just want to show an option how to prevent people from logging in with local admin.
We created a domain account and
  • removed this account from domain users
  • add this account to group "local admins"
  • make domain group "local admins" member of local group "Administrators"
  • script runs daily that changes password (14 chars)
  • same script sets the account to expire in 24hrs
  • daily password is listed on an intranet site

Additionally a computer script creates a local admin, renews the random password every 2 Months and pushes the password to a SQL DB - in case of emergency.

I was also interested in how to disable interactive logon preserving the ability to elevate rights with this account. Too bad that this is impossible.

HTH
 
Last edited:

My Computer My Computer

At a glance

W7 Enterprise
Computer type
PC/Desktop
OS
W7 Enterprise
Back
Top