Re: admin privs only for desktops.



In news:5DE99DBE-66CC-48B9-9042-5F0FC1F0BC7C@xxxxxxxxxxxxx,
realitychx <realitychx@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
I would like to create a domain user that has admin privs on all
desktops in my domain. I don't want this user to have domain admin
privs/server admin privs and i don't want to have to go to each
desktop (200) and add the user to the local admin group. Can i do
this via GP... or is there a group in AD this user can be a member of
that will accomplish this?

thanks for the info guys... Have a great day!

What I generally do in a domain is to create two groups - LocalAdmins and
LocalPower Users.
I add those groups to the appropriate local workstation groups using a
computer startup script set in a GPO -

net localgroup administrators DOMAIN\localadmin /add
net localgroup "power users" DOMAIN\localpower /add

And then all I need to do is put the users I wish into the appropriate AD
groups. It's better than assigning privileges to domain users directly on
the workstations, as it gives you a lot more flexibility when you want to
make changes.

You can also look into using Restricted Groups for this via GPO -

Note that questions like this would probably be best posted in an AD group
or a group policy group.




.



Relevant Pages

  • Re: Deploying icon to numerous desktops
    ... > Deus DNE wrote: ... >> Is there a simple way to deploy an icon onto all desktops on win2kPro ... >> admin is done by bespoke system. ... others and drop the icon. ...
    (microsoft.public.win2000.general)
  • Security Updates with Local Users Problem
    ... We are about to rollout W2KPro to desktops and for the ... Security Updates, which only work when the user has Admin ... I have considered using "RUNAS" in the script to ...
    (microsoft.public.win2000.security)
  • Re: ACL on GPO link
    ... prevent them from unlinking your GPO. ... The gpLink attribute is monolithic in that each link ... A person who can manage links everywhere is aswell an admin ... ... I conclude that you cannot prevent an AD administrator from ...
    (microsoft.public.windows.group_policy)
  • Re: Manually added user rights assignments
    ... Are you attempting to set this is a GPO of AD that is applied ... OU (containing the servers) not to the domain and are ... Also, if you have TS installed in admin mode on W2k, or you ... > Have been trying to add the buit-in Admin accounts of my members servers ...
    (microsoft.public.windows.group_policy)
  • Re: ACL on GPO link
    ... To take it a step further from what Mark has said, if, for example, an administrator was not domain admin equivalent and could not take ownership of any AD object and change its permissions, you could prevent them from the writing the gpLink attribute on the domain NC head. ... But, because of the way links are stored, they would also not be able to add any new links to the domain, nor remove other GPO links. ...
    (microsoft.public.windows.group_policy)

Quantcast