Re: Local admin group
From: Torgeir Bakken \(MVP\) (Torgeir.Bakken-spam_at_hydro.com)
Date: 12/01/04
- Next message: Jerry Bryant [MSFT]: "Microsoft Security Bulletin for December 1, 2004"
- Previous message: jetwanin: "Requirements for Domain Controller Certificates from Third-Party CA"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 01 Dec 2004 15:08:31 +0100
MC wrote:
> Guys & girls
> How can I define a list of global security groups that are members of the
> local admins group. I don't want the users to be domain admins but to be
> local admins on all clients.
Hi
We add "NT Authority\Interactive" in the local Administrators group
to let all domain users automatically be local admins when they log
on to a computer interactively.
This is more secure than adding "Authenticated Domain users ",
"Domain Users", "NT AUTHORITY\Authenticated Users" or any other
global security group because you avoid the issue with cross
network admin rights (remote access) that these groups introduces.
-- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: http://www.microsoft.com/technet/scriptcenter/default.mspx
- Next message: Jerry Bryant [MSFT]: "Microsoft Security Bulletin for December 1, 2004"
- Previous message: jetwanin: "Requirements for Domain Controller Certificates from Third-Party CA"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|