Re: Delegating Add/Remove program authority

From: Paul Bergson (pbergson_at_mnpower.com)
Date: 11/26/04


Date: Fri, 26 Nov 2004 08:10:33 -0600

You could use restricted group
    This user/group is a member of

Only apply it to the specific machine. Since it is only for 1 machine it is
not a good idea to use a gpo. I would stick with doing it manually.

Computer Configuration
    Windows Settings
        Security Settings
            Restricted Group
                Group - Blah Blah is a member of Administrators

Unless you restrict this to a specific machine this group (Blah Blah) will
be a local admin of all machines that apply this gpo

-- 
Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA
This posting is provided "AS IS" with no warranties, and confers no rights.
"Kitey" <Kitey@discussions.microsoft.com> wrote in message
news:181B926D-C794-460B-A768-ACA0D2EED991@microsoft.com...
> We have a user that needs to have the right to add/remove software on a
> workstation on the domain. At the moment the user is added to local
> administrators group manually but is there a way to allow the user this
right
> via AD. I have looked through delegation and GPO but can't seem to find
that
> option.
> Thanx


Relevant Pages

  • Re: Desktop Admin - HELP
    ... restricted group in my GPO and refreshed my policy and all should be good... ... local admin rights... ... ALSO, i created a brand new GPO to use, and it had the same results... ...
    (microsoft.public.win2000.active_directory)
  • Group policy tatooing with restricted group ? or strange behaviour !
    ... Configuration 2 --> During three months, we have changed this GPO and the restricted group was defined witht the "member of" parameter so a user was able to add himself to the local admin group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Where is Local Admin group in GPO?
    ... You can also use the member of function in restricted groups to add users ... which do not affect the already in place users in the local admin group. ... You can add a user to the local Admins group via a gpo using the ... From the help topic on the item: "When a restricted Group Policy is ...
    (microsoft.public.windows.group_policy)
  • Re: Delegating Add/Remove program authority
    ... are located in an OU called OED I have set up a GPO for OED. ... with "oedbuild" as member. ... > Unless you restrict this to a specific machine this group (Blah Blah) will ... > be a local admin of all machines that apply this gpo ...
    (microsoft.public.win2000.active_directory)
  • Re: Local Admin on workstation
    ... except making them local admin through restricted group in GPO, they won't be able to install software. ... You may use GPO to deploy software through GPO without making them admin. ... You may also just use psexec to make a silent install remotely.. ...
    (microsoft.public.windows.server.active_directory)