Re: Domain Users to have Local Admin rights



Hi,

Brooster posted a solution to your question.

What I would like to add is a warning against using domain administrator
accounts to logon to user computers.
So simply put -- don't use accounts that have domain administrator
permissions for logging on to client computers. Use these accounts only for
working on domain controllers.
For logging on to client computers create new accounts (e.g. admin-mike,
admin-greg, etc) and add them to a group called e.g. Help Desk. Now add this
group to Local Administrator group by using solution proposed by Brooster.

--
Mike
Microsoft MVP - Windows Security

"RedPenguin" <redpenguin@xxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1254qjd2uso6j84@xxxxxxxxxxxxxxxxxxxxx
Ok we recently installed Microsoft Server 2003 Enterprise Edition on our
PC. The whole domain is working and everyone has thier own login that
works. The only thing is, those users do not have local admin privledges
on the PCs they logon to.

We wish to have a handful of users, HelpDesk, that when they login to any
machine, they automatically get admin privledges on the workstation.

We tried playing with Group Policy Editor but nopthing at all will work.



.



Relevant Pages

  • Re: Domain Password Security
    ... accounts need to use complex passwords and minimum of ntlmv2 should be used for lan ... Services Client and configuring authentication level on Domain Controller Security ... controllers if you have all W2K/XP computers. ... I also recommend you enable auditing of account logon and logon ...
    (microsoft.public.win2000.security)
  • Re: Domain Password Security
    ... Domain Controller Security ... >controllers if you have all W2K/XP computers. ... >administrator accounts only when needed to, ... account logon and logon ...
    (microsoft.public.win2000.security)
  • Re: User Login
    ... The accounts are currently disabled, but they will be enabled when they link ... "Meinolf Weber" wrote: ... accounts for them to logon to their email. ... they will be able to logon to any computers ...
    (microsoft.public.windows.server.active_directory)
  • Re: OWA 2003 is only accessable during workingdays
    ... Is it the same when you log in from a client on the network? ... thinking of AD Users and Computers, Properties, Accounts, Logon Hours. ...
    (microsoft.public.exchange.misc)
  • Re: Access denied error when I want to access the event log from a rem
    ... I'm in the local administrators group of both computers. ... I logon to the ... domain and I'm a domain administrator. ...
    (microsoft.public.windows.server.general)