Re: Local administratotor rights on target machines
- From: "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx>
- Date: Sat, 26 Aug 2006 10:30:41 -0700
What you apparently did was to make that resticted group definiition
in a GPO linked to location where it influences more than just the
intended machines (like to domain object instead of linking to OU
that holds only the machines you intend to target).
The other thing that you did was to replace the membership of
the administrators group with what you had specified in the GPO,
at least is I correctly read your statement
In 'restricted groups' [under Computer Configuration -> Windows
settings -> Security settings] added 'administrators' group, and
made this account member of this group.
Instead, your said your requirement was
I have to provide a domain account with localThat does not say anything about making it the only admn, or
administrator privileges on a subset of machines.
about removing other accounts that may be member on the
subject machines.
See
http://support.microsoft.com/?id=810076
or Laura's response to the thread in this newsgroup immediately
before this one.
"Ram" <ramprakashj@xxxxxxxxxxxxxxxx> wrote in message
news:1156492673.443763.235030@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Dear All,
As part of requirement, I have to provide a domain account with local
administrator privileges on a subset of machines. To accomplish this, I
created a GPO for those machines.
In 'restricted groups' [under Computer Configuration -> Windows
settings -> Security settings] added 'administrators' group, and
made this account member of this group.
Though I achieved my purpose, I feel that I gave elevated privileges
to this domain account. Kindly suggest me any better solution where I
can give this domain account only local administrator privileges on the
targeted computer accounts?
Regards
Ram
.
- Follow-Ups:
- References:
- Prev by Date: GP Management station?
- Next by Date: Re: GP Management station?
- Previous by thread: Local administratotor rights on target machines
- Next by thread: Re: Local administratotor rights on target machines
- Index(es):
Relevant Pages
|