Re: Local Admin

From: Torgeir Bakken \(MVP\) (Torgeir.Bakken-spam_at_hydro.com)
Date: 10/19/04


Date: Tue, 19 Oct 2004 20:11:06 +0200

Jody Stoll wrote:

> Hello,
> Is it possible through Group Policy to add the 'domain Users' group to
> the 'Local Administrators' group on all Windows XP Pro workstations in a
> 2003 AD Domain
Hi

For security reasons, I suggest you add "NT Authority\Interactive"
and not "Domain Users" to the local Administrators group.

We add "NT Authority\Interactive" in the local Administrators
group to let all domain users automatically be local admins
when they log on to a domain computer interactively.

This is more secure than adding "Authenticated Domain users ",
"Domain Users" or "NT AUTHORITY\Authenticated Users" because you
avoid the issue with cross network admin rights (remote access)
that these groups introduces.

-- 
torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of
the 1328 page Scripting Guide:
http://www.microsoft.com/technet/scriptcenter/default.mspx


Relevant Pages

  • Re: Full access without Administrative rights
    ... Administrators group to let all domain users automatically be local ... avoid the issue with cross network admin rights ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windows.group_policy)
  • Re: Full access without Administrative rights
    ... Administrators group to let all domain users automatically be local ... avoid the issue with cross network admin rights ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.security)
  • Re: Script to enumerating list of Local Admingroup member of all d
    ... How to Configure a Global Group to Be a Member of the Administrators Group on ... This is more secure than adding "Authenticated Domain users", ... avoid the issue with cross network admin rights ... torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
    (microsoft.public.windows.server.scripting)
  • RE: OpenDataSource "Unspecified Error" when connecting to local Excel
    ... Are there any another hidden permissions required for the OpenDataSource ... the file is on the local Sql Server. ... > Even if I add domain users to the server administrator role, ... > local administrators group on the Sql Server? ...
    (microsoft.public.sqlserver.connect)
  • Re: Local Admins
    ... We add NT Authority\Interactive in the local Administrators group to let all ... domain users automatically be local admins when they log on to a computer ... Microsoft MVP Scripting and WMI, ...
    (microsoft.public.security)