Re: adding to local usergroup after first login.



Hi Bruce,

Thanks for the reply.

Since the question is not clearly understood i guess, hereby i am briefing
you the details what i am expecting.

As i told in a single domain we are using around 100 PCs in 3 floors. We as a
support engineer providing the users (domain user a/c) as power users in the
local pc. Also, software installations and troubleshooting we are undertaking
everything through remotely from our PC using Dameware Mini Control.

Some of the users are frequently will interchange their seat location (not pc)
So, when they logon to the PC in new location with their domain user name
and password (hope its known that their user name will not be in any local
group in that PC).

So, if any user in that new location ask for software installation, we
connect their pc remotely using Dameware Minicontrol tool. We (our domain
user id is having full admin rights). Since as i said their domain user id is
not available in any of the local group in that pc, we couldn't able to
connect their pc from our pc.

So, we physically go to their place and add their user name in power users
group and then start the installation remotely from our computer.

I tried by asking them to do themselves to add their name in power users /
users (local)group in that pc. But when they issue (net localgroup "Power
Users" theirusername /add" in command prompt its saying that Access Denied to
them.

So, is there any other way to do that themselves ? FYI, in our domain for
domain users (other than us) the management console will not open as its
denied through our domain group policy.

Any help will be highly appreciated.


Bruce Chambers wrote:
Hi,

[quoted text clipped - 3 lines]
However if any user require admin rights for their PCs we give admin rights
to their user name in that pc through the myadmin user only.

Is the "myadmin" account a local account created on each machine? If
so, just broadcast it's password to all of the employees.

Since some of the users are changing their pcs frequently .....

Is there no IT department to control such things? Employess shouldn't
be given such free rein with expensive equipment.

.... whenever they ask
admin rights to their PCs we are going to their location and giving admin
rights. We couldn't able to connect their pcs remotely through Dameware
Remote control since their user id is not even in power user group in that
local machine since their are logging to that pc with their ID for the first
time.

That would not affect your ability to contact via DameWare. (Or using
the built-in MMC, for that matter.)

So, my question is, is there any way is there so that the user itself add
their user name in any one of the localgroup in that pc ?

Only if that user already has full administrative privileges, already.

May one ask what you're really trying to accomplish seeking to grant
your users such elevated privileges? (Beyond utterly compromising your
network's security, that is.)


--
chandra

Message posted via WindowsKB.com
http://www.windowskb.com/Uwe/Forums.aspx/windowsxp/200709/1

.



Relevant Pages

  • Re: "you do not have access to log onto this session" error
    ... group like "power users" and still gives the domain users group remote ... This posting is provided "AS IS" with no warranties, and confers no rights. ... If I add the user account to the Remote Desktop> group I can log on fine, but then the user isn't a member ... I then also>>> grante the same rights to domain users (the user I am ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Dameware - Eavesdropping to easy
    ... It only works for DameWare. ... Basically I can push the "Remote Client Agent" to all the ... first you get rid of the network administrators. ... >your resume on your personal private printer and pack up ...
    (microsoft.public.win2000.security)
  • Re: Remote Access Errors
    ... Make sure that the power users are added to the Remote Desktop Users (System ... Microsoft MVP: Windows Server ... > at System.Web.UI.Control.RenderChildren(HtmlTextWriter writer) ...
    (microsoft.public.windows.server.general)
  • Re: Remotely adding user to a localgroup
    ... remove the user from the "Power Users" group? ... is there anyway of causing net localgroup to run on the remote PC? ... Connect to the remote system dive with an administrative level user... ...
    (microsoft.public.windowsxp.security_admin)
  • Re: User forced Logoff remotely
    ... Well if they are all Domain Admins, ... I think if they are power users, ... permission for remote shut down. ... I know he's logging them off, but the way I found out you ...
    (microsoft.public.win2000.general)