none
Active directory users

    Question

  • Hi All,

    Hope all are doing good,

    We as a company has some security requirements need to block net user and wmic commands in our domain for all users except administrartor to restrict rights of users is there any possibility that we can achieve this requirement.

    Looking forward for your response in the above query.

    Regards,

    Syed Muhammad Safwan

    Wednesday, May 9, 2018 6:17 AM

All replies

  • Really appreciate if anybody could help on above query

    Regards,

    Safwan Syed.

    Thursday, May 10, 2018 3:52 AM
  • Hi,

    You could restrict the "net.exe" and "wmic.exe" by group policy for specific users.

    Here is the policy:

    User Configuration/Administrative Templates/System/Don't run specified Windows applications

    And net.exe is under windows/system32 folder,  wmic.exe is under Windows\System32\wbem folder.


    Best Regards
    Cartman
    Please remember to mark the replies as an answers if they help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com

    Friday, May 18, 2018 2:29 AM
    Moderator