Originally posted by: mechBgon
Using a <broken record> Limited-class account </broken record> rather than a Computer-Administrator-class account is a zero-performance-impact reinforcement to put your browser, IM proggie and email program in a "safety cage." You might try that out if you're looking to run a "lite" and less-effective antivirus program.
I'm putting that on my to-do list, going to test it out in the next couple of months.
#1 Administrator's worst nightmare - inconsistency. One of my profressors in colleged often used the phrase "if you're going to do something wrong, do it wrong consistently". That way once you discover the problem, you can backtrack it and fix it.
I'm noticing that in the last few years we've been recreating our images too often, and keep making changes to the setup procedure, and users are installing more junk than ever. I've been trying to sell the team on the idea of going to an all-Citrix solution, so the machines have minimal setups and all the administration/updates can be done locally/centrally. But until that happens (probably never), we need to at least get the machines to a consistent state where users have little impact on them on their own.
The problem is we've tried using Power Users years back, and even that didn't have enough permissions to run some of our accounting software so we have to make them full admins. What a tricky mess...