Re: Local Admin access through Active Directory



You can add the user to the local administrators group on the computers that
you want to do this on. One easy way would be to put the computers into an
OU and link a Group Policy to that OU and configure Restricted Groups so
that a global group [will be Restricted Group] you create is added to the
administrators group [will be member of] . Then add the user to the global
group. The link below explains in much more detail. --- Steve

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

"Jon LaBarge" <jonlabarge@xxxxxxxxxxx> wrote in message
news:OT6dnPdWGHA.1192@xxxxxxxxxxxxxxxxxxxxxxx
Is there a way to give a user the ability to install programs on local PCs
without adding them to the Domain Admins group?

We need someone to install software on 20+ PCs, but do not want them to
have domain admin rights. Can this be done without having to go PC to PC
giving them local access?

Thanks in advance!



.



Relevant Pages

  • Re: Group Policy
    ... administrators group of all computers in the domain. ... restricted groups, however this GP setting will remove all the users ... to add a domain group to the local administrators group ...
    (microsoft.public.windows.server.active_directory)
  • Re: Win 2003 Local Admin Problem
    ... You should have defined a built-in Administrators group as a restricted ... I added the local administrators group on my PC. ... Windows Server - Directory Services ... >>>> You can use Restricted Groups feature of the GP to add Domain Admins ...
    (microsoft.public.windows.group_policy)
  • adding a global group to the local administrators through a group policy
    ... The computers that apply are Windows 2000 with service ... existing members from the group. ... group will be in the Administrators group on each 2K, XP, ... >local administrators group (just add the group to the ...
    (microsoft.public.win2000.group_policy)
  • Re: Basic User Setup
    ... You could user the computer configuration "restricted groups" to create a global ... restricted groups to enforce the membership of the domain computers in that OU ... want to wipe out current membership of the local administrators group in that OU ...
    (microsoft.public.win2000.group_policy)
  • Re: Help needed setting up roaming administrator
    ... Another option is a "startup" script implemented via Group Policy to ... computers within the scope of influence of the policy such as the Organizational Unit ... Administrators group use. ... > default users and groups in the local Administrators group. ...
    (microsoft.public.win2000.security)