Educause Security Discussion mailing list archives

Re: Local Admin Accounts


From: Gary Flynn <flynngn () JMU EDU>
Date: Wed, 16 Sep 2009 14:37:56 -0400

-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Guy Pace
Sent: Wednesday, September 16, 2009 2:04 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Local Admin Accounts

We dropped _all_
users to power users, removed access to local policy and made sure that
domain admin group was part of the local admin group.

I'm surprised you saw a lot of benefits just dropping the users
to power users rather than all the way to regular users. If
I remember correctly, power users can modify the HKEY local
system registry RUN entries to persist, add files to the windows
directory, add various browser extensions, and a lot of other
things most malware tries to do.

Current thread: