Add groups to Local Admin group

From: Dan Ireland (direland69@yahoo.com)
Date: 01/08/03


From: "Dan Ireland" <direland69@yahoo.com>
Date: Wed, 8 Jan 2003 11:29:24 -0800


I think I figured it out.

I created a .bat file with the following command...

NET LOCALGROUP Administrators /ADD "mydomain\IS"

Then added this .bat as a Startup Script in Group Policy
for the OU that contains the target computers. Seems to
be working. HOORAY!

  Dan

>-----Original Message-----
>We are running all Windows 2000 workstations in a Windows
>2000 domain.
>
>By default, the Domain Admins group becomes a member of
>the local PC's Administrators group. I have a need for
>another domain group ("IS") to also be a member of the
>local Administrators group. I do not want the IS group
to
>be a member of Domain Admins. Is there some way I can
>push this change out to all of the workstations (about
>300) instead of visiting each one?
>
>Group Policy or SMS would be my preferred method if
>possible.
>
>Thanks,
>
> Dan
>
>.
>



Relevant Pages

  • Re: Opening workstation event view = Access Denied
    ... You can add domain groups (or user accounts) to local groups using Restricted Groups in a GPO. ... In a domain of any size, you might NOT want the people that administer workstations to be Domain Admins. ... You can then designate which user accounts are workstation administrators without also granting them administrative rights to the whole domain. ... being a member of the Domain Admins group does NOT necesarily mean you are an administrator on the domain member computer. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to make give cross-domain "Domain Admins" permissions
    ... that "Domain Admins" do. ... Domain Admins don't have any special permissions, ... member of administrators on every domain member and the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Opening workstation event view = Access Denied
    ... Domain Admins gets added to the local group called Administrators. ... being a member of the Domain Admins group does NOT necesarily mean you ... Remote Desktop Users pmd.local/Builtin ...
    (microsoft.public.windows.server.active_directory)
  • Re: difference in groups
    ... Administrators is a built-in group. ... group, except that local, when considered on DCs, covers all DCs. ... Domain Admins is a global group that is automatically added to the ... administrators group of every domain member. ...
    (microsoft.public.windows.server.active_directory)
  • RE: software to control domain administrators
    ... "Does anyone know any software to control, audit, or restrict access or privileges to domain administrators." ... I will restate my mantra differently, If you can not trust someone to be in a position of complete un-adulterated control of your network, then they should not be in that position. ... >(assuming we are talking about NT/AD Domain Admins) ...
    (Security-Basics)