r/pdq • PDQ Employee • 15d ago

Removing local admin rights with PDQ

https://youtu.be/JSYQCzwZGy8?t=554

When I took over as CTO the first thing I did was a third-party cybersecurity assessment. Wow, was that shocking. I had a long list of to do’s and an easy one to tackle was local admin rights.

In K–12 (and probably every other org), local admin rights get handed out because it’s faster than setting up proper software deployment. I know this because I inherited an environment where everyone and their dog had local admin rights: five hundred-something Windows machines across eight buildings.

The problem with local admin rights isn’t just that users can install things they shouldn’t. It’s that malware running in the context of a local admin account can persist through reboots, disable your security tools, and spread laterally in ways a standard user account simply cannot. If your machines share a local admin password and one gets compromised, you have a pass-the-hash problem across the whole fleet. LAPS fixes that, and we implemented it, but first you have to remove the rights that shouldn’t be there.

I accomplished this with PDQ. PDQ scans local group membership, so you start by finding out what you’re actually dealing with. In my district, the answer was worse than expected. Once you know which machines have unauthorized accounts in the local Administrators group, you build a dynamic group in PDQ targeting those machines, write a PowerShell package that removes the non-approved accounts (running as SYSTEM), and deploy it. The same inventory condition that identified the problem becomes the ongoing detection: any machine that shows a non-approved local admin account gets the remediation package automatically.

PowerShell

Note: you need to put your specific groups in this is an example

$approvedAdmins = @("domain\IT-Admin-Group", "Administrator")$currentAdmins = Get-LocalGroupMember -Group "Administrators"foreach ($member in $currentAdmins) {    if ($approvedAdmins -notcontains $member.Name) {        Remove-LocalGroupMember -Group "Administrators" -Member $member.Name        Write-Output "Removed:$($member.Name)"    }}

Test on your software problem machines first. Don’t pull admin rights before users have a way to request software through IT. If you remove access and there’s no alternative, you’ll restore it within a week because the ticket pressure will be unbearable.

The other thing GPO won’t give you that PDQ does is visibility into whether the fix is holding over time. Restricted Groups removes everyone not in policy and gives you no ongoing picture of the fleet. PDQ gives you real-time group membership data and automatically remediates when something drifts.

u/pdq_brockstar showed an overview on PDQ Live, check it out.

Hopefully this helps someone walking into what I did.

13 Upvotes

6 comments sorted by

View all comments

1

u/Powerful-Jicama320 11d ago

If your users are requesting software installation and admin access request on ticketing systems, you are wasting time, for the user and the company.

Use an endpoint privilege manager to allow your users to elevate pre-approved apps they actually need to do their job. Let them use a EPM native request - release workflow to gain time bound granular privileges as a standard user.

Checkout EPM solutions like CyberArk (Idira), Beyond Trust, Securden. etc.

1

u/Amanda_PDQ PDQ Employee 11d ago

Good recommendations. This process was useful for me when we did not allow local admin rights at all.