Re: administrating workgroup from domain

From: Richard G. Harper (rgharper_at_email.com)
Date: 09/30/04


Date: Thu, 30 Sep 2004 07:01:18 -0400

I think you've got it. Let's pick on poor Bob as an example.

You have a domain account named "Bob". Bob is a normal domain user and has
no domain administrator rights. If you go to the Workgroup computer he
wants to connect to over the network and use the Local User Manager
(lusrmgr.msc) to add Bob's name and password to the Administrator group on
the local machine, he will be able to connect to it remotely and have
Administrator rights on the Workgroup PC, but still will have no Domain
rights other than Domain User.

-- 
Richard G. Harper [MVP Win9x]  rgharper@email.com
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all.  Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm
"Mtek" <jimlily2001@yahoo.com> wrote in message 
news:1CEE3F1D-A332-47F5-92DA-B625390960AC@microsoft.com...
> Hmm. I may be dense, if I understand what you are saying.
>
> I could create an local account on my domain machine with no additional
> rights buy regular users.
>
> Then create an local account on the workgroup machine with admin rights 
> with
> the same local logon name as the domain machine.
>
> I could then log in locally on the domain machine connect to the workgroup
> machine and have local administrative rights on the workgroup machine but 
> not
> any domain rights.
>
> Or otherwords the workgroup machine cannot access any domain assets. Which
> is what I want anyway.
>
> I do not have to change any local security settings to get complete local
> access, and the workgroup is still isolated from the domain.
> ?
>
>
> "Richard G. Harper" wrote:
>
>> It doesn't work that way.  You can connect to a workgroup PC with an 
>> account
>> that is an administrator on that computer and get administrator access, 
>> but
>> just because both accounts are administrators in their separate security
>> spaces doesn't mean that rights transfer from one to the other.
>>
>> -- 
>> Richard G. Harper [MVP Win9x]  rgharper@email.com
>> * PLEASE post all messages and replies in the newsgroups
>> * for the benefit of all.  Private mail is usually not replied to.
>> * My website, such as it is ... http://rgharper.mvps.org/
>> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>>
>>
>> "Mtek" <jimlily2001@yahoo.com> wrote in message
>> news:9C008DEA-A321-437A-92E8-DAEB29F75E66@microsoft.com...
>> >I am not work this work this week so I can't try this. But seeing as I 
>> >have
>> > an local admin account on the workgroup machine and a local admin 
>> > account
>> > on
>> > the domain machine, shouldn't I be able to log in locallally on the 
>> > domain
>> > machine then administrer the workgroup machine?
>> >
>> > "Richard G. Harper" wrote:
>> >
>> >> An administrator on a remote PC may not be an administrator on the 
>> >> local
>> >> PC.
>> >> The account names, passwords and rights must match between all clients
>> >> for
>> >> the same rights to be granted on the client computer.
>> >>
>> >> -- 
>> >> Richard G. Harper [MVP Win9x]  rgharper@email.com
>> >> * PLEASE post all messages and replies in the newsgroups
>> >> * for the benefit of all.  Private mail is usually not replied to.
>> >> * My website, such as it is ... http://rgharper.mvps.org/
>> >> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>> >>
>> >>
>> >> "Mtek" <jimlily2001@yahoo.com> wrote in message
>> >> news:E599F916-48DC-4DF7-AA11-5DBDE429D975@microsoft.com...
>> >> > Shouldn't there be some way of validating an administrator on the
>> >> > remote
>> >> > machine locally?
>> >> >
>> >> > "Richard G. Harper" wrote:
>> >> >
>> >> >> You can't.  The reason you can administer a domain is because the
>> >> >> security
>> >> >> settings are centrally held.  On a workgroup each workstation keeps
>> >> >> its
>> >> >> own
>> >> >> security settings.
>> >> >>
>> >> >> -- 
>> >> >> Richard G. Harper [MVP Win9x]  rgharper@email.com
>> >> >> * PLEASE post all messages and replies in the newsgroups
>> >> >> * for the benefit of all.  Private mail is usually not replied to.
>> >> >> * My website, such as it is ... http://rgharper.mvps.org/
>> >> >> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>> >> >>
>> >> >>
>> >> >> "Mtek" <jimlily2001@yahoo.com> wrote in message
>> >> >> news:A16B3922-0C13-4851-B53B-BCED601DDE4C@microsoft.com...
>> >> >> > How can I set up a workgroup on our network that I can
>> >> >> > administer(remote)
>> >> >> > from my admin domain workstation?
>> >> >> >
>> >> >> > I would like to be able to have admin access as I do in the 
>> >> >> > domain.
>> >> >> > But
>> >> >> > still leave the workgroup/user not able to share/use domain
>> >> >> > resources.
>> >> >> >
>> >> >> >
>> >> >>
>> >> >>
>> >> >>
>> >>
>> >>
>> >>
>>
>>
>> 


Relevant Pages

  • Re: administrating workgroup from domain
    ... >> to add Bob's name and password to the Administrator group ... >> Administrator rights on the Workgroup PC, but still will have no Domain ... >> * PLEASE post all messages and replies in the newsgroups ... >>> Then create an local account on the workgroup machine with admin rights ...
    (microsoft.public.windowsxp.network_web)
  • Re: Administrator righs in safe mode
    ... I did set up an administrator account and password when I bought thecomputer. ... I also set up a user account for my son with limited rights. ... Somehow through Safe Mode he figured out how to change his account so that he ...
    (microsoft.public.windows.mediacenter)
  • Re: Event 1202 Warnings after Renaming Administrator Acct on SBS2003
    ... Administrator account is referenced. ... retained in two locations - Active Directory and Global Policy. ... setting/User Rights Assignment and the default setting for SBS2003. ...
    (microsoft.public.windows.server.general)
  • Re: Cannot install new program anymore
    ... >Open your control panel and look at the Users applet. ... >Administrator or Limited? ... >Administrator account and you created your account, ... >administrative rights. ...
    (microsoft.public.windowsxp.general)
  • Re: about sysclean from trend micro (Rusty & Marcy)
    ... When trying to clean a system it is *BEST* to use the Administrator's account or preferably ... an account with Administrative rights. ... Administrator & one other (which is the first user acc't that was ...
    (microsoft.public.security.virus)