"Brian Smith" <i...@flrsbx.com> wrote in message
news:201a01c15bdc$f15448d0$9be62ecf@tkmsftngxa03...
>.
>
A user can install some applications even if they are only Users. However,
it is possible to restrict Power Users so they got the same rights on
filesystems and registry as a normal user, and they will find it a lot more
difficult to install applications.
For this second option, locate basicwk.inf in
%systemroot%\security\templates. Create a copy and change the template to
give Power User the same access rights as Users got. This security template
can then be loaded in a GPO in AD to be applied to local machines. You'll
then have the case that the users are Power Users on the machine, but on
their machine they only got normal Users rights to registry and filesystem.
Giving them Power Users right also gives them some other built-in rights,
like sharing folders. Built-in rights is documented in technet.
--
Of course, this posting wouldn't be complete without a nice, juicy
disclaimer from our lawyers: This posting is provided "AS IS" with no
warranties, and confers no rights. You assume all risk for your use. © 2001
Microsoft Corporation. All rights reserved.
"Brian Smith" <i...@flrsbx.com> wrote in message
news:350701c15c8d$f6194580$b1e62ecf@tkmsftngxa04...