Re: Local Administrators group
- From: "Mark Heitbrink [MVP]" <spam-only@xxxxxxxxxxxxxxxxxxxxx>
- Date: Sat, 17 Sep 2005 11:04:25 +0200
Hi,
spin schrieb:
> Some of our users need to run some programmes that need to wright to reg but
> because they are domain users they dont get the right so we would like to
> make them members of the local administrators group but i cant find any
> thing in the a policy to do this.
In Computer Config you will find:
Services, Registry, Filesystem and Restricted Groups.
In this place you can administrate the local permissions centrally.
You can monitor the missing permissions for example with filemon and
regmon from Sysinternals and only give change or full permission
to the objects, where a user is usually not allowed to.
Most programmes just need change permission in their installation
directory and the HKLM\Software\NameofProduct Hive. Because they
place temp files there or change entries.
There are only a few applications, that really need local admin rights.
HTH
Mark
--
Mark Heitbrink - MVP Windows Server
Homepage: www.gruppenrichtlinien.de
W2K FAQ : http://w2k-faq.ebend.de
PM: Vorname@Homepage, Versende-Adresse wird nicht abgerufen.
.
- Follow-Ups:
- Re: Local Administrators group
- From: Gary Chell
- Re: Local Administrators group
- References:
- Local Administrators group
- From: spin
- Local Administrators group
- Prev by Date: Re: Apply Group policy to all domain users but not users in group "a"
- Next by Date: Re: Apply Group policy to all domain users but not users in group "a"
- Previous by thread: Re: Local Administrators group
- Next by thread: Re: Local Administrators group
- Index(es):
Relevant Pages
|