Event banner
AMA: Finding your way to “cloud first”
Event Ended
Wednesday, Jun 05, 2024, 08:30 AM PDTEvent details
How can you accelerate your transition to cloud-native endpoint management for your Windows estate? What’s the logical order for moving workloads? We’re here to answer your big questions, specific qu...
Heather_Poulsen
Updated Dec 27, 2024
Andreas_Wi401
Jun 05, 2024Copper Contributor
What is the best way to prevent giving users local admin rights. I know there are solution on the horizon like Endpoint Privilege Management but still only covering a small portion like exe. What is the best approach till EPM is fully featured and covers "all" scenarios? Just adding a user account to local admin group?
- Char_CheesmanJun 05, 2024Bronze Contributor
Thanks for participating in today's session of AMA: Finding your way to “cloud first”! For reference, the panel covered your question at 28:40.
- SimonHalpinJun 05, 2024Copper ContributorThis is something we are just working through also. We looked at EPM and PAM. I have now suggested that the endpoints arent used for developement and instead we are going to remove their local admin rights on the endpoint and all developement work will move to Cloud PCs/AVD setup.
- SimonHalpinJun 05, 2024Copper ContributorHave you looked at Windows LAPs?
- Andreas_Wi401Jun 05, 2024Copper Contributorwe did and use it. I dont want to give out the use the user / pwd to use. From my point of view I dont have any control a user while having the knowledge of user / pwd. For me the challenge is that users are used to have local admin rights. They are developper and want to install testing tools etc. I want to prevent that and get rid off it.