Win2003 General Network Password???

Heeter

Overclocked Like A Mother
Joined
Jul 8, 2002
Messages
2,732
#1
Hi Guys,

A client of mine has Win2003SBS, and approx 8 workstations in his office. Win2000Pro and WinXPPro as clients.

My question: even though each workstation has each their own username and password to logon to the machine, Can the SmallBusinessServer still issue each and every workstation one general Username/password that overrides the client side? One username/password that can get into each machine no matter what the user/pass is on the client end.

The reason asking is that NOD32 Enterprise Edition would of deployed a lot smoother from the server if we had better access to the workstations.

Thanks in advance,


Heeter
 

DwarfData

OSNN Addict
Joined
Feb 4, 2004
Messages
135
#3
Heeter,

Any account that is a member of the Domain Admin group can be used to log on to any workstation and have Administrator rights.

Is this what you are after?
 

Heeter

Overclocked Like A Mother
Joined
Jul 8, 2002
Messages
2,732
#4
Using the domain user/pass will get into all clients? Really, thanks,

I would like to "Gain control" of all workstations during deployment of apps, like the antivirus. Was going around to each workstation gathering their usernames and passwords.

Heeter
 

DwarfData

OSNN Addict
Joined
Feb 4, 2004
Messages
135
#5
Save your feet. Use Remote Desktop to connect to the machines. Also, Small Business Server can be configured to install any required software on all it's clients.
 

madmatt

Bow Down to the King
Political User
Joined
Apr 5, 2002
Messages
13,312
#6
As long as the desktops are joined to the domain then yes. The Administrator account is located in the Users OU.
 

Heeter

Overclocked Like A Mother
Joined
Jul 8, 2002
Messages
2,732
#7
Thanks a lot, Guys,

Thanks for the help. Will look for the OU next time I am in that office. Remote desktop, should of thought of that last night, too.


Heeter
 

fitz

Woah.. I'm still here?
Staff member
Political User
Joined
Apr 26, 2004
Messages
4,082
#8
If they are part of the domain, the domain\Domain Admins group is automatically added to the local administrator group when they join the domain.

If the user is setup as a local administrator, they can, technically, remove the domain admins group from the local administrator group in which case, your domain admin account would not have access to the machine.

You can setup "restricted groups" in your Group policy to force a domain group into a local group (MS Link on Restriced groups).

You could (of course) also deploy your software via GPO's as well.. or SMS or any other deployment software..
 

kcnychief

█▄█ ▀█▄ █
Political User
Joined
Apr 8, 2005
Messages
16,948
#9
Just wanted to chime in a bit about a few things....

First of all, and this is only opinion and my preference, on my servers that run AV's and push applications/updates to clients, I don't use Domain Administrator accounts. I created a special Group that contains all service accounts that need to have just enough rights to do their job. Maybe I'm a bit ****, but I don't like having excessive rights for tasks that don't need them.

I pushed out NOD32 about two weeks ago and I love the customization you have and how you can build your own packages. I had a few weird errors at the first time I tried communicating with the clients, but nothing I wasn't able to resolve :)
 

Heeter

Overclocked Like A Mother
Joined
Jul 8, 2002
Messages
2,732
#10
Thanks Guys,

I am interested in how your setup goes about, KC. through a special group and all clients are in the workgroup?

Thanks,

Heeter
 

kcnychief

█▄█ ▀█▄ █
Political User
Joined
Apr 8, 2005
Messages
16,948
#11
Nothing to do with clients really, I just have a Group on the network called "Maintenance" (just my preference, really has no meaning), that has sufficient network priveleges to carry out specific actions.

I have a few user accounts in this group, the one related to NOD32 being called "avupdates". This way I don't need to use members of the Domain Admin or local Admin groups, which would give more access rights than needed IMO.

Group memberships and settings come down through the network.
 

Members online

No members online now.

Latest profile posts

Perris Calderon wrote on Electronic Punk's profile.
Ep, glad to see you come back and tidy up...did want to ask a one day favor, I want to enhance my resume , was hoping you could make me administrator for a day, if so, take me right off since I won't be here to do anything, and don't know the slightest about the board, but it would be nice putting "served administrator osnn", if can do, THANKS

Been running around Quora lately, luv it there https://tinyurl.com/ycpxl
Electronic Punk wrote on Perris Calderon's profile.
All good still mate?
Hello, is there anybody in there? Just nod if you can hear me ...
Xie
What a long strange trip it's been. =)

Forum statistics

Threads
62,000
Messages
673,421
Members
89,024
Latest member
swipk8