Add additional domain group to local admins groups?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Is using "restricted groups" the only way to automate adding additional
groups other than just "domain administrators" to the local administrators
on all domain workstation?
We would like to have a group with members that are local admins on all
workstations and also have the right to add and remove machines names to the
domain, but not be domain admins.

I have heard that there is some hotfix that was needed to prevent restricted
groups created from a GPO from flushing out the existing local admins on the
machines.
I was told this is that patch even though it doesn't actually say on the
page that's what it does.
http://support.microsoft.com/default.aspx?kbid=810076

We need to add new default local admins without removing the local admins
already on the machines (assigned users need to keep their admin rights in
order to run some apps on their PCs).
Would that hotfix have to be run on every machine on the domain or only on
the machine that was used to create the GPO?


.



Relevant Pages

  • Re: Installing Software without being Local Admin?
    ... Some of you may remember back in June I posted a topic entitled 'Network Computer Games on Business Machines' which detailed the problem we were having with some of our users installing software & games on their machines, as they were local admins. ... So I need to find someway of allowing users to install fix packs/re-install the software, without giving them full local admin access. ...
    (microsoft.public.security)
  • Re: Global Account for Installing Software
    ... You could create a sub-ou within the main ou for these machines and use ... restricted groups to delegate a subadmin to manage these machines. ... If you want them to be local admins so they can perform maintenance than you ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group Policy and Local Administrator
    ... > users on their local machines. ... > maintain these users as local admins on their machines only, ... > making them power users on other computers on the network. ...
    (microsoft.public.win2000.active_directory)
  • Re: Rename Workstation Accounts
    ... If users logon to the domain, and they are local admins of the machines, you ... For instance I disable a control panel ... >> with the standard naming convention are being changed. ...
    (microsoft.public.windowsxp.security_admin)