Re: How can I allow Domain User Accounts Admin rights on their loc

From: Colin Nash [MVP] (x_at_x)
Date: 10/17/04


Date: Sun, 17 Oct 2004 02:07:08 -0400


"Patrick Parks" <PatrickParks@discussions.microsoft.com> wrote in message
news:410C3CE1-5309-4A41-8854-B04251101147@microsoft.com...
> Thanks, you say not recommended, why? Will this be a security threat to
> the
> server?
>

Ideally, users should not be administrators of workstations. Some times
this is necessary due to what the do, or due to office politics, but
generally it is best to limit them to the least privileges that they
actually need. If *your* account is a member of Domain Admins, then you
should already have admin rights when you log on. If there are other people
who will providing tech support but who don't need to manage the domain
itself, it would be a good idea to create a group on the domain called "IT
Staff" or something, and make this group a member of each workstation's
Administrators group. Put yourself and any other technicians/admins in that
group.

-- 
Colin Nash
Microsoft MVP
Windows Printing/Imaging/Hardware 


Relevant Pages

  • Re: AD Design
    ... Within a new domain the domain admins can administer the complete domain, ... If you add them to the Enterprise admins, they are able to administer the complete forest. ... By default, this group is a member of the Administrators group on all domain controllers, all domain workstations, and all domain member servers at the time they are joined to the domain. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Customize User Rights for Domain Admins Group
    ... workstation administrators members of the Domain Admins group for them to ... Add your new group and Domain Admins. ... Then link this GPO to your OU's that contain your workstations and your ...
    (microsoft.public.windows.server.active_directory)
  • Re: Opening workstation event view = Access Denied
    ... You can add domain groups (or user accounts) to local groups using Restricted Groups in a GPO. ... In a domain of any size, you might NOT want the people that administer workstations to be Domain Admins. ... You can then designate which user accounts are workstation administrators without also granting them administrative rights to the whole domain. ... being a member of the Domain Admins group does NOT necesarily mean you are an administrator on the domain member computer. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to make give cross-domain "Domain Admins" permissions
    ... that "Domain Admins" do. ... Domain Admins don't have any special permissions, ... member of administrators on every domain member and the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local Admin on desktops
    ... add the user accounts that you want to be administrators on the workstations to this group ... "The Member Of list specifies groups in which the restricted group is ... If you remove a group from the Member Of list, the restricted group is ... administrators) without giving them Domain Admin privelidges? ...
    (microsoft.public.windows.server.active_directory)