[457] in winnt

home help back first fref pref prev next nref lref last post

Re: Admin privs restricted to workstation in domain

daemon@ATHENA.MIT.EDU (bcvernon@MIT.EDU)
Mon Dec 13 11:25:28 1999

From: bcvernon@MIT.EDU
Message-Id: <9912131624.AA14649@MIT.EDU>
Date: Mon, 13 Dec 1999 11:27:11 -0500
To: Tom Fitzgerald <tfitz@MIT.EDU>, Don Nelson <dnelson@psfc.MIT.EDU>
Cc: ntpartners@MIT.EDU
In-Reply-To: <199912100159.UAA22336@sligo.mit.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"

>But why not give the user the administrator password?  It's not really
>any different, except for the hassle of logging out and logging back
>in again, and (if the user is conscientious), can avoid much damage
>caused by mistakes.
Hi Tom,

In general, giving out the administrator password is a bad idea, especially
if all the workstation administrator passwords are syncronized.  And it is
different, especially because logging on as yourself provides useful
auditing information.  If the user does not know what he/she is doing,
which would lead any administrator to question their having administrative
rights, then it would be best to grant permission to a user to perform the
few functions they need to perform (adding printers, installing programs,
etc) instead of giving them full administrative rights.  Don neither
includes the NT experience level of the user in question nor explains the
functionality this user needs to gain from having those priviledges, so it
is impossible to provide him with the best answer, from an administrator's
perspective. 

Of course, everyone has their own philosophy and take on these matters, so
feel free to disagree!

All the Best,
Bryant


home help back first fref pref prev next nref lref last post