none
Denying access to PC

    Question

  • Hi,

    I have AD on server 2008 and PCs with Windows 7, 8.1 and 10.

    A person boots PCs from USB, resets administrator's password, adds user to administrators groups (local on PC) and installs software.


    Is there a way to deny doing this by GPO or other means? 

    Some computers are laptops and have to be used not being connected to our network. Also USB ports have to operate.

    Thank you in advance.

    Wednesday, November 02, 2016 8:23 AM

Answers

All replies