Giving your employees the freedom to try new tools, listen to music while they work, or visit social media sites in their off time will improve their morale and enhance their productivity. But that flexibility can quickly lead to disaster if they wind up ruining their computers, bogging them down with garbage apps, or worse.
So how do you balance keeping your employees happy with maintaining control of your company’s assets?
The Decision
One strategy is to deny your employees all administrative control over their computers. Such a restriction would reduce the risk of your computers being waylaid by buggy apps and malware, because no one would be able to install anything. The drawback is that you–or your designee–would have to do all of the installing for them. That can be a time-consuming process, especially if you’re deploying a new application to your entire workforce–even if it’s just a handful of employees. Then you have to consider periodic security patches, bug fixes, driver updates, and upgrades. And don’t forget the need to install drivers and software for new peripherals, such as printers and scanners.
Granting Administrator Access
Before you open up everyone’s computer for unfettered use, establish a baseline software environment that will be standard for each staffer. Set a policy that allows employees to augment their computers with new applications but prohibits them from uninstalling or disabling the baseline programs–especially the antivirus and antimalware tools, a secure Web browser, an office suite (unless you use a cloud app, such as Google Docs), and whatever proprietary software your small business needs to function.
Then, use an application such as DriveImage XML (free for private use; a five-user commercial license costs $100) to clone the system drive on each class of computer you’ll deploy. Your goal is to create an image of each type of desktop system in your office, from standard administrative machines to function-specific desktops (video-editing workstations, for example). If disaster strikes or an employee renders their computer unusable, you can quickly restore it to its original configuration.
The Power of Group Policy Editor
Local administrator privileges seem unstoppable, but there is a means by which you can exert fine control over the Windows operating system. The secret is to use Windows 7’s Group Policy Editor. Log on with the user’s admin credentials, and type gpedit.msc in the Windows search box (you’ll find it in the Start menu) and then press the Enter key. From here, you can disable access to critical Windows elements entirely–including the Control Panel–or you can choose which components you wish to allow your employees to modify. For instance, you might give them the ability to switch screensavers, but not to change printers or uninstall programs.
Don’t discount the power of the Group Policy Editor. If you’re the slightest bit hesitant about letting employees run wild on their systems, this handy Windows feature offers the ounce of control you need to keep your systems running smoothly. You’ll find all of the settings worth browsing and editing under Group Policy Editor’s ‘Administrative Templates’ folder in the User Configuration menu.
Finer Administrative Control
Do you need a third-party application to control your users’ activity on their systems? Not really. However, if you discover that recalcitrant employees with administrator privileges are circumventing your Windows-based access controls, you might want to look into stronger solutions. For example, if you install Faronics’ Deep Freeze ($35.50 per year) on employee machines, the program will restore each system to an identical snapshot every time the PC restarts. Or you could provide staffers with a virtual desktop that would give them the freedom to install their personal programs in a sandboxed environment.
As long as you’re willing to invest a bit of time setting up the right configurations, granting your employees administrator privileges on their small-business PCs won’t necessarily lead to chaos. You can even control admins without making your employees feel as though they’re working under parental controls from nine to five.