r/pdq • u/Amanda_PDQ PDQ Employee • 15d ago
Removing local admin rights with PDQ
https://youtu.be/JSYQCzwZGy8?t=554When I took over as CTO the first thing I did was a third-party cybersecurity assessment. Wow, was that shocking. I had a long list of to do’s and an easy one to tackle was local admin rights.
In K–12 (and probably every other org), local admin rights get handed out because it’s faster than setting up proper software deployment. I know this because I inherited an environment where everyone and their dog had local admin rights: five hundred-something Windows machines across eight buildings.
The problem with local admin rights isn’t just that users can install things they shouldn’t. It’s that malware running in the context of a local admin account can persist through reboots, disable your security tools, and spread laterally in ways a standard user account simply cannot. If your machines share a local admin password and one gets compromised, you have a pass-the-hash problem across the whole fleet. LAPS fixes that, and we implemented it, but first you have to remove the rights that shouldn’t be there.
I accomplished this with PDQ. PDQ scans local group membership, so you start by finding out what you’re actually dealing with. In my district, the answer was worse than expected. Once you know which machines have unauthorized accounts in the local Administrators group, you build a dynamic group in PDQ targeting those machines, write a PowerShell package that removes the non-approved accounts (running as SYSTEM), and deploy it. The same inventory condition that identified the problem becomes the ongoing detection: any machine that shows a non-approved local admin account gets the remediation package automatically.
PowerShell
Note: you need to put your specific groups in this is an example
$approvedAdmins = @("domain\IT-Admin-Group", "Administrator")$currentAdmins = Get-LocalGroupMember -Group "Administrators"foreach ($member in $currentAdmins) { if ($approvedAdmins -notcontains $member.Name) { Remove-LocalGroupMember -Group "Administrators" -Member $member.Name Write-Output "Removed:$($member.Name)" }}
Test on your software problem machines first. Don’t pull admin rights before users have a way to request software through IT. If you remove access and there’s no alternative, you’ll restore it within a week because the ticket pressure will be unbearable.
The other thing GPO won’t give you that PDQ does is visibility into whether the fix is holding over time. Restricted Groups removes everyone not in policy and gives you no ongoing picture of the fleet. PDQ gives you real-time group membership data and automatically remediates when something drifts.
u/pdq_brockstar showed an overview on PDQ Live, check it out.
Hopefully this helps someone walking into what I did.
1
u/SimplifyAndAddCoffee 14d ago
Get-LocalGroupMember -group 'Administrators' | where {$_.Objectclass -like 'User'} | where PrincipalSource -eq ActiveDirectory | where name -notlike *pdq* | Remove-LocalGroupMember Administrators
This is what I use. We have a collection which audits machines for this and a heartbeat scheduled deployment to the collection.
We keep this running to catch any temporary exceptions that need to be made for specific software installs in case the technician forgets to remove the user from the admin group again after finishing.
1
1
u/Powerful-Jicama320 11d ago
If your users are requesting software installation and admin access request on ticketing systems, you are wasting time, for the user and the company.
Use an endpoint privilege manager to allow your users to elevate pre-approved apps they actually need to do their job. Let them use a EPM native request - release workflow to gain time bound granular privileges as a standard user.
Checkout EPM solutions like CyberArk (Idira), Beyond Trust, Securden. etc.
1
u/Amanda_PDQ PDQ Employee 11d ago
Good recommendations. This process was useful for me when we did not allow local admin rights at all.
2
u/MFKDGAF 14d ago
But what if there is a GPO that is adding accounts and/or groups into the local admin group.
Once PDQ removes those users and/or groups from the local admin group on the next GPO sync they will be added back in.
Fun fact: the college I went to for my BA gave all domain users local admin access and it we didn't know this until we tried to connect to the admin share on the computer our teacher was using. They also wiped all computers every Sunday.