Re: User/Group Administration

From: Roger Abell (mvpNOSPAM@asu.edu)
Date: 08/15/02


From: "Roger Abell" <mvpNOSPAM@asu.edu>
Date: Wed, 14 Aug 2002 18:59:03 -0700


"Chris Stainer" <cstainer@jscsc.org> wrote in message
news:347901c243ae$1d1a5270$9ae62ecf@tkmsftngxa02...
> Following a successful migration to Windows 2000, we are
> starting to make use of dedicated groups to administer the
> domain, i.e. Desktop Support Admins, Hardware Admins, that
> can configure and administer computers but whom are not
> members of the Domain Admins local group. However, we did
> not include the two aforementioned groups into the local
> (client) Administrators group, so they are having problems
> connecting to the workstations remotely, or install
> applications without having to use the local administrator
> account (i.e. using RunAs, etc.)
>
> Although myself and my colleagues are aware of logging
> locally, via a deskside visit or via connecting in the MMC
> (high TCO), I was wondering if anyone had a cool script
> that would allow us to remotely add the two groups into the
> local (client) Admins group, i.e. via VBScript or command-
> line batch files (low TCO), or can this be done via Group
> Policy???
>
> Any advice would be much appreciated, by myself, our
> systems administrators and our efficient helpdesk guys.
>
> Regards,
>
> Chris J. Stainer
>

The following may work for you, if you are comfortable
with all of the accounts being admins full-time on the
workstations. This is not always advisable, depending
on the size of the groups.

If the workstations are in one or more OUs, you can use
an OU linked GPO to control the membership in the local
Administrators group. Do this by defining a Restricted
Group, naming it Administrators but being careful not to
select the listed Administrators (which would be the domain
group). Keep in mind that this will control precisely what is
the membership of the Administrators group and into what
the group is itself a member, so be complete (Administrator,
Domain Admins, spare-local-acct, domain-hardware-admins,
and so forth).

--
Roger Abell
MVP (Windows Platform)  Associate Expert
The Expert Zone - www.microsoft.com/windowsxp/expertzone


Relevant Pages

  • Re: Allow Admins to log on to W2K Desktop with Admin Rights
    ... You might want to try posting to ... >>You need to have all your workstations under a single ... > administrators domain\helpdesk ... >>membership or add to it. ...
    (microsoft.public.win2000.security)
  • Re: 2003 Domain Admins in NT4 Domain
    ... it seems that you only add the 2003\Domain Admins ... admin rights on a workstation in the NT4 domain. ... After adding these two groups into NT4's workstation's local Administrators ... >workstations are actually using a different DNS server. ...
    (microsoft.public.windows.server.migration)
  • Re: Enumerate Admins
    ... "Richard Mueller" wrote: ... It reveals membership due to group nesting, ... You can specify the Distinguished Name of the Administrators ... Admins" group, etc. ...
    (microsoft.public.scripting.vbscript)
  • Re: Weird security problem in my WIn2K domain
    ... > group Administrators on computer XXX: ... > Of course my account is a member of Enterprise Admins and also Domain ... > After failing to do this simple task from my own workstations, ...
    (microsoft.public.windows.server.security)
  • Re: Weird problem in my Win2K Active Directory
    ... MVP for Windows Server - Software Distribution ... > group Administrators on computer XXX: ... > Of course my account is a member of Enterprise Admins and also Domain ... > After failing to do this simple task from my own workstations, ...
    (microsoft.public.windows.server.active_directory)