I don't know how to do this, but I can fill in some info on SBS so maybe someone else can.
A machine running SBS *must* be a PDC. This is written in stone. There is no way to de-promote SBS or join it to an existing domain.
Here's my hack-kluge-workaround: If you don't have too many clients, go around and disable their USB controllers in CMOS, then set passwords on the CMOS setup program.
Time to go off on a tangent:
I presume you are concerned about some employee bringing in their own flash drive and carting off sensitive documents. If you're that paranoid about such matters, SBS might not have been the best choice...whereas with 2003 Standard, you can enable Terminal Services...and dumb down all your desktops...all sensitive material remains only on the server.
ok, tangent over, back to your thread.
|