NRoach44@lemmy.mltoSysadmin@lemmy.world•recommends for Headless windows install and configuration?English
2·
1 year agoNot quite, I have to go through out of box, and then join it to the domain, but then yes!
Applies security policy, install apps, disables bloat, login in with central username and pass, get mapped drives etc
It means that if someone breaks out of your container, they can only do things that user can do.
Can that user access your private documents (are these documents in a container that also runs under that user)?
Can that user sudo?
Can that user access SSH keys and jump to other computers?
Generally speaking, the answer to all of these should be “no”, meaning that each group of containers (or risk levels etc) get their own account.