|
Problem Description:
The client computer was added to the domain, and a domain account with ordinary permissions was added to the local administrator group of the client.
Local login or domain account login, domain administrator does not need domain administrator privileges, as long as the local administrator privileges? ?
If local login is restricted, login directly with a domain account, you must add the domain account to the client's local administrator group, so
There is no problem installing software on the client side, but in this way, this domain account can create a new local administrator account,
You can quit again, so it feels very contradictory.
I would like to ask experts, how to solve this problem, restrict the following computers from leaving the domain? |
|