Re: Changing account from admin to standard



On 2007-11-03, D P Schreber <schreberdp@xxxxxxxxxx> wrote:
On 2007-11-03, TH O <tho@xxxxxxxxxxxxxx> wrote:
Honest question - I know this is the preferred technique on Windows but
is it really required on OS X? Any admin level changes you try to make
will all prompt you for a username and password so what's the harm in
staying in your admin account day to day?

The problems are more theoretical than real. I've been running as an
admin user since day 1 of the 10.0 beta. So has every other osx user
I know. I also routinely run linux as a user with sudo access, which
is effectively the same thing.

It is not effectively the same thing. I use a non-admin account on
my iMac but I have put it in the sudoers file so I can sudo from
the account. It is still a non-admin account. Admin accounts, unlike
non-admin accounts, are members of group 79 (appserverusr), 80 (admin)
and 81 (appserveradm). This gives them direct access to files (without
authenticating) which are not accessible to non-admin users. There
are other differences too, but the basic point is that putting a
non-admin account in the sudoers file does NOT make it an admin
account, even effectively.

Ian

--
Ian Gregory
http://www.zenatode.org.uk/ian/
.



Relevant Pages

  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: cant verify disk
    ... She went to DU, and when she pressed "verify disk", it asked her user ... Disk Utility has required an administrator name and password for certain ... This is clearly a task which requires admin privileges, ... seriously mucked up with her user account settings in the NetInfo ...
    (comp.sys.mac.system)
  • Re: Wscript within VBA
    ... One box is running VBA code,. ... One box is a domain controller, or has an account trusted to manipulate AD ... >> It posts a form to an ASP page, ... >> Since what you want to do sounds like it will require admin privileges, ...
    (microsoft.public.vb.database)
  • Re: Administrators Group in Local Users and Groups
    ... using the Account Operators group is doing your work like you ... * create separate admin accounts to perform admin tasks, ... * Create an OU for the Admin roles and the admin tasks ... > I do not see a problem with adding junior admins to the Account Operators ...
    (microsoft.public.windows.server.active_directory)

Loading