As long as the workstations don't need to share printers or other file shares, you should be able to accomplish this by revoking the "Access this computer from a network" rights for everyone except Domain Admins. If you are using XP (maybe W2K too), there is also an option to "Deny access to this computer from the network" that you could add the Staff group into.
Greg -----Original Message----- From: Alexander Kha Do [mailto:[EMAIL PROTECTED] Sent: Friday, March 14, 2003 1:01 PM To: NT 2000 Discussions Subject: Remote Admin shares If someone is a local admin of a machine, is there a way to restrict their ability to access the c$ share of the machine? Our situation is such that we have a "staff" group which has local admin rights to the standard workstations. Is there any way to make it so that they cannot UNC to the C$ of their coworkers' computers, but we can sitll get in as Domain Admins? ~Alex ------ You are subscribed as [EMAIL PROTECTED] Archives: http://www.swynk.com/sitesearch/search.asp To unsubscribe send a blank email to %%email.unsub%% ------ You are subscribed as [EMAIL PROTECTED] Archives: http://www.swynk.com/sitesearch/search.asp To unsubscribe send a blank email to [EMAIL PROTECTED]
