Archived from groups: microsoft.public.windowsxp.security_admin (More info?)
> My company has previously set up each user in the local administrator
> group. THIS WAS A MISTAKE!
> We want to take away their rights to download and run non-certified
> programs, and no downloading.
> Problem is... any files they created as local admins, no longer are
> accessible when I remove them from the administrators group.
Take ownership of the files/folders as an admin - and set the security
For apps that won't behave - see www.sysinternals.com - FileMon and RegMon.
> What are my options? How can I remove their rights to download and
> install? Power users? and have them able to use and access the
> documents they have created previously?
Don't use power users, either. It is rarely needed.
> Thanks in advance, Chris