Re: Give Domain Users Local Admin Rights

From: Mike (anonymous_at_discussions.microsoft.com)
Date: 05/10/04


Date: Mon, 10 May 2004 07:54:08 -0700


>-----Original Message-----
>Mike wrote:
>
>> I added DOMAIN USERS to the local administrators group
on
>> each PC. This seemed to work, but with 1 issue. Now
each
>> user has full rights to EVERY local machine in the
>> Domain, via the "hidden" admin share "C$". (not good).
>>
>> How can I grant Local Admin rights to just the PC they
>> are logged on to without giving them Local Admin
rights
>> to other user's PC's?
>Hi
>
>There exists a very simple solution for this:
>
>We add "NT Authority\Interactive" in the local
Administrators group
>to let all domain users automatically be local admins
when they log
>on to a computer interactively.
>
>This is more secure than adding "Authenticated Domain
users",
>"Domain Users" or "NT AUTHORITY\Authenticated Users"
because you
>avoid the issue with cross network admin rights (remote
access)
>that these groups introduces (as you have experienced).
>
>
>--
>torgeir, Microsoft MVP Scripting and WMI, Porsgrunn
Norway
>Administration scripting examples and an ONLINE version
of
>the 1328 page Scripting Guide:
>http://www.microsoft.com/technet/community/scriptcenter/d
efault.mspx
>.
>Thanks Torgeir,

That's excactly the kind of fix i was looking for.

Mike



Relevant Pages

  • Re: Local admin domain user
    ... >while still remaining standard domain users. ... admin rights be default if you joined a domain...). ... group "Domain Users" to the administrators group. ...
    (microsoft.public.win2000.security)
  • Re: users as local pc admin-
    ... Be nice if software writers would actually take this into account though so ... either domain users - for everyone, or the praticular user, is a member of ... the administrators group. ... local admin if not, ...
    (microsoft.public.windows.server.sbs)
  • Re: users as local pc admin-
    ... either domain users - for everyone, or the praticular user, is a member of ... the administrators group. ... long as you are logged on as a local or domain admin), ... and to remove local admin if desired? ...
    (microsoft.public.windows.server.sbs)
  • Re: Weird Issue
    ... Logon to the client as a local admin. ... Logon with your domain account you just added locally. ... I do that by including the> Domain Users group in the local Administrators group of each machine. ...
    (microsoft.public.win2000.active_directory)
  • Re: Computer Management Security Problem
    ... Check:To view a user's group membership for a domain, use the resource kit utility Showgrps.exe.. ... Users group to the Administrators group? ... either using the Default Domain GPO or a GPO at the domain level to ... By using a GPO at the domain level and specifying that Domain Users are ...
    (microsoft.public.win2000.security)