How to block nonadmin users from viewing Local User and Groups

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hi All
Users can connect to a remote PC using computer management console and
view Local User and groups.
How to block nonadmin users from remotely viewing this information

Thanks in Advance
Kiran
 
Users can connect to a remote PC using computer management console because
they have the account on the remote PC. However, you can restrict by not
letting them to run mmc.exe

User Config\Administrative Templates\System\Don't run specified Windows
applications

Prevents Windows from running the programs you specify in this setting. If
you enable this setting, users cannot run programs that you add to the list
of disallowed applications. This setting only prevents users from running
programs that are started by the Windows Explorer process. It does not
prevent users from running programs, such as Task Manager, that are started
by the system process or by other processes. Also, if you permit users to
gain access to the command prompt, Cmd.exe, this setting does not prevent
them from starting programs in the command window that they are not permitted
to start by using Windows Explorer. Note: To create a list of disallowed
applications, click Show, click Add, and then enter the application
executable name (e.g., Winword.exe, Poledit.exe, Powerpnt.exe).

BR,
Denis
 
Hi Denis
Thanks for the reply.
When I followed your suggestion it blocked everyone including administrator
from running the mmc.exe.
How can I block only non-admin users from running it.

Thanks
Kiran
 
Back
Top