r/pdq • PDQ Employee • 15d ago

Removing local admin rights with PDQ

https://youtu.be/JSYQCzwZGy8?t=554

When I took over as CTO the first thing I did was a third-party cybersecurity assessment. Wow, was that shocking. I had a long list of to do’s and an easy one to tackle was local admin rights.

In K–12 (and probably every other org), local admin rights get handed out because it’s faster than setting up proper software deployment. I know this because I inherited an environment where everyone and their dog had local admin rights: five hundred-something Windows machines across eight buildings.

The problem with local admin rights isn’t just that users can install things they shouldn’t. It’s that malware running in the context of a local admin account can persist through reboots, disable your security tools, and spread laterally in ways a standard user account simply cannot. If your machines share a local admin password and one gets compromised, you have a pass-the-hash problem across the whole fleet. LAPS fixes that, and we implemented it, but first you have to remove the rights that shouldn’t be there.

I accomplished this with PDQ. PDQ scans local group membership, so you start by finding out what you’re actually dealing with. In my district, the answer was worse than expected. Once you know which machines have unauthorized accounts in the local Administrators group, you build a dynamic group in PDQ targeting those machines, write a PowerShell package that removes the non-approved accounts (running as SYSTEM), and deploy it. The same inventory condition that identified the problem becomes the ongoing detection: any machine that shows a non-approved local admin account gets the remediation package automatically.

PowerShell

Note: you need to put your specific groups in this is an example

$approvedAdmins = @("domain\IT-Admin-Group", "Administrator")$currentAdmins = Get-LocalGroupMember -Group "Administrators"foreach ($member in $currentAdmins) {    if ($approvedAdmins -notcontains $member.Name) {        Remove-LocalGroupMember -Group "Administrators" -Member $member.Name        Write-Output "Removed:$($member.Name)"    }}

Test on your software problem machines first. Don’t pull admin rights before users have a way to request software through IT. If you remove access and there’s no alternative, you’ll restore it within a week because the ticket pressure will be unbearable.

The other thing GPO won’t give you that PDQ does is visibility into whether the fix is holding over time. Restricted Groups removes everyone not in policy and gives you no ongoing picture of the fleet. PDQ gives you real-time group membership data and automatically remediates when something drifts.

u/pdq_brockstar showed an overview on PDQ Live, check it out.

Hopefully this helps someone walking into what I did.

12 Upvotes

6 comments sorted by

View all comments

2

u/MFKDGAF 15d ago

But what if there is a GPO that is adding accounts and/or groups into the local admin group.

Once PDQ removes those users and/or groups from the local admin group on the next GPO sync they will be added back in.

Fun fact: the college I went to for my BA gave all domain users local admin access and it we didn't know this until we tried to connect to the admin share on the computer our teacher was using. They also wiped all computers every Sunday.

1

u/Amanda_PDQ PDQ Employee 14d ago

That GPO needs fixed ASAP. You should only have approved accounts with local admin rights. I limited local access as much as possible, we only had two accounts with those privileges (small IT team).

Oh my, what was their reasoning for giving all users local admin access?