Re: administrative privileage Q.

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/14/05


Date: Thu, 14 Apr 2005 11:32:57 -0500

You could use Group Policy Restricted Groups at the Organizational Unit
Level. Assuming you are using at least W2K SP4 you could create an OU and
place the computers in the OU where you want him to be a local admin. Then
configure Restricted Groups and use "member of" for administrators group.
Create a domain global group, add the user to that group, and add it to the
"member of" for administrators. Otherwise you could use a Group Policy
"startup" script for those computers using the command [ net localgroup
administrators "mydomain\user" /add ] to add that user to the local
administrators group on those computers. --- Steve

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html
http://support.microsoft.com/default.aspx?kbid=810076
http://support.microsoft.com/default.aspx?scid=kb;en-us;198642

"David" <NOSPAMDavidGerst@anti-spam.tempco.com> wrote in message
news:%23s4vpvQQFHA.1472@TK2MSFTNGP10.phx.gbl...
> Is there a way to make them local administrators w/o having to go around
> and
> manually add the account to each machine?
>
>
> "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
> news:OC$yZ8HQFHA.1340@TK2MSFTNGP10.phx.gbl...
>> You can add any domain account to the local administrators group on any
>> domain computer other than domain controllers which will give the user
>> admin powers on just that computer where you add them to the local
>> administrators group. There is no way to do such on domain controllers.
>> About the best you can do in that case if give the user additional user
>> rights and add them to privileged groups such as server operator which
>> still will not allow them to install most software on a domain
>> controller. You can also use Group Policy to assign .msi applications to
>> a computer/user or publish an application for a user. Assigned/published
>> applications will be automatically installed if assigned to a computer or
>> can be installed by a user even if they do not have admin powers. ---
>> Steve
>>
>>
>> "David" <NOSPAMDavidGerst@anti-spam.tempco.com> wrote in message
>> news:uttThFHQFHA.3384@TK2MSFTNGP10.phx.gbl...
>>> How would I go about granting someone local machine (workstations)
>>> administrator privileages without making them a domain admin which would
>>> then grant them full access to the servers?
>>>
>>> I saw in group policy there is a setting where you can allow a
>>> user/group to install device drivers. I did not see any such setting
>>> that would allow them to install applications to the desktop.
>>>
>>> thanks.
>>>
>>> - David
>>>
>>
>>
>
>



Relevant Pages

  • Re: Giving admin rights to a subset of computers
    ... computers exist in the 'Computers' folder under the domain. ... created a restricted group 'ATL-RG'. ... > I would create a new Group Policy in that OU or modify one that you already ... > that global group to be "this group is a member of" administrators group. ...
    (microsoft.public.win2000.security)
  • Re: Group Policy
    ... administrators group of all computers in the domain. ... restricted groups, however this GP setting will remove all the users ... to add a domain group to the local administrators group ...
    (microsoft.public.windows.server.active_directory)
  • Re: Basic User Setup
    ... You could user the computer configuration "restricted groups" to create a global ... restricted groups to enforce the membership of the domain computers in that OU ... want to wipe out current membership of the local administrators group in that OU ...
    (microsoft.public.win2000.group_policy)
  • Re: Default Security Groups
    ... I then follow your steps to apply restricted groups, ... to the computers administrator group i.e not altering any groups/users ... Domain Admins group will be added to local administrators group by ... Click the Group Policy tab, click NEW, and then name the policy. ...
    (microsoft.public.windows.server.migration)
  • Re: Default Security Groups
    ... I then follow your steps to apply restricted groups, ... computers within a domain. ... Domain Admins group will be added to local administrators group by ... Click the Group Policy tab, click NEW, and then name the policy. ...
    (microsoft.public.windows.server.migration)