Changing process priorities of normal users



We have a Windows 2000 Advanced Server and wish to be able to adjust the
process priorities of users without adding them to the Domain Admins
group. According to
<http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/core
/fned_ana_spmq.mspx?mfr=true>, by default only members of the Domain
Admins or Administrators groups can have their process priorities
changed.

I tried to change the security policies to allow Everyone to have their
process priorities changed. I opened "Local Security Settings >
Security Settings > Local Policies > User Rights Assignment > Increase
Scheduling Priority" and added Everyone in addition to Administrators to
have this right. I noticed, however, that in the "Effective Policy
Setting" indicator, Administrators are checked but Everyone is not.

Does this mean there is a domain-level policy in effect that is
overriding the local policy? If so, how do I go about accessing it and
changing it? I am a domain admin -- though a newbie to domain
administration (my experience is mostly with Unix and Max OS X Server).
Some tips would be helpful.

I also tried restarting the server in question, but the local security
policies I had set didn't take effect.


-- Bert Sierra, IT Manager
Fann Contracting, Inc.
.



Relevant Pages

  • Re: Domain Admins group missing
    ... If I follow right, you need to add the Domain Admins group ... for your new SBS03 domain to the local administrators group on each PC? ... Windows Server MVP ... The only listed groups are the local computer ...
    (microsoft.public.windows.server.migration)
  • Re: Changing process priorities of normal users
    ... Administrators the right to adjust normal users process priorities (by ... User U's process priorities unless User U was a member of Domain Admins. ...
    (microsoft.public.win2000.security)
  • Help!Group Policy
    ... I've setup some group policies on my windows 2000 ... a win 2000 server. ... remove the restrictions for administrators, domain admins ...
    (microsoft.public.win2000.security)
  • Re: Domain Admins Group -- Trying to trim membership
    ... very trusted and competent people being domain admins. ... a qualified regular domain user by managing AD object permissions. ... server, installing a Certificate Authority, etc. usually are not done every ... controllers are only domain controllers running DNS and not also a print, ...
    (microsoft.public.win2000.security)
  • Re: Password Problem with Server Login
    ... We periodically reboot our server and had ... login with the Administrator account like we usually do and the ... We also tried an account ... however we have other users who are members of the "Domain Admins". ...
    (microsoft.public.windows.server.active_directory)