I think the OP meant he was looking for suggestions other than "don't put them in the local administrators group".
:) Don Guyer Systems Engineer - Information Services Prudential, Fox & Roach/Trident Group 431 W. Lancaster Avenue Devon, PA 19333 Direct: (610) 993-3299 Fax: (610) 650-5306 don.gu...@prufoxroach.com -----Original Message----- From: Terry Dickson [mailto:te...@treasurer.state.ks.us] Sent: Monday, April 27, 2009 2:25 PM To: NT System Admin Issues Subject: RE: Prevent mods to HKLM\Software\Microsoft\CurrentVersion\Run Even if you did do that, as a local admin they could just take ownership of the folder and boom they are writing to the registry key again and the startup folder again. -----Original Message----- From: David Lum [mailto:david....@nwea.org] Sent: Monday, April 27, 2009 1:15 PM To: NT System Admin Issues Subject: Prevent mods to HKLM\Software\Microsoft\CurrentVersion\Run Is there a GPO way to prevent something from modifying this registry key? If I could prevent that and stuff from auto-populating the \Startup folder for "all users" I would be a happy camper. Tools like Spybot can do it, but that's not enterprise grade (read, centrally manageable). McAfee has a product that can do it - and we even have it and are licensed for it, but it's interface is so atrocious I'd probably nuke half my systems just attempting it. I'm looking for something other than "not local admin". David Lum // SYSTEMS ENGINEER NORTHWEST EVALUATION ASSOCIATION (Desk) 971.222.1025 // (Cell) 503.267.9764 ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~