Re: User Rights

From: Gabe Matteson (gmatteson_at_rounder.com)
Date: 08/29/04

  • Next message: Jeffrey: "Re: Domain Controller wont see itself"
    Date: Sat, 28 Aug 2004 20:49:07 -0400
    
    

    you can use gpo and use restricted groups to put a group such as IT Suppport
    in any group on the local machines such as power users or administrators so
    that they are only local admins on domain workstations (DEPENDING on which
    OU you apply the gpo to)

    "KC" <KC@discussions.microsoft.com> wrote in message
    news:ADE1A119-AE1F-496E-86DA-1DD750A48A05@microsoft.com...
    > Hi,
    >
    > I have a Windows 2003 AD (Windos Server 2003 domain function level) and
    > all
    > my clients are either Windows XP or Windows 2000. What I would accomplish
    > it
    > to give few users that I have grouped together to be able to install and
    > uninstall applications on the workstations, and nothing else.
    >
    > Currently, I gave them 'Domain Admins' rights but disable a lot of
    > functionalities that domain admin can do through Group Policy, such as
    > disable features in MMC and software restriction. I don't know of other
    > ways
    > to accomplish this besides giving them 'Domain Admins' privilege. The
    > delegate control features does not have I was looking for.
    >
    > Does anyone have a better solution to accomplish this?
    >
    > I have read one suggestion is to use 'Restricted Group' but I don't know
    > how
    > it works. What actually is 'Restricted Group'?
    >
    > Any idea and help will be greatly appreciated. Thank you in advance.


  • Next message: Jeffrey: "Re: Domain Controller wont see itself"

    Relevant Pages

    • Re: Computer Management Security Question
      ... And the GPO with this restricted group definition ... > No, they are not domain administrators, they only administrators on their ... own machines. ... >> Sounds like you made your users domain admins instead of admin of their ...
      (microsoft.public.windows.server.security)
    • Re: Access Denied in some Workstations for Domain Admins
      ... > you can't add a local user id back to a local group using this method ... Admins" to be a member, instead, make "Domain Admins" the restricted group ... >> Is this the proper command? ...
      (microsoft.public.windows.server.active_directory)
    • Re: Remove Domain Admins ability from "Delegation Of Control"
      ... Domain Admins and administrators are very powerfull groups. ... There is no point of having a group that would only be able to delegate all ... Then i plan on removing the the Read Members, ... > modify the restricted group membership to this "restricted group ...
      (microsoft.public.win2000.active_directory)
    • Re: Remove Domain Admins ability from "Delegation Of Control"
      ... I was just wondering whether it is possible to remove the Domain Admins ... Then i plan on removing the the Read Members, ... "Restricted Group Admins" or similar and give it permission to ...
      (microsoft.public.win2000.active_directory)
    • Re: Restricting Domain Admins
      ... domain admins group to the level that I require. ... > restricted group in a GPO with higher priority on the Domain Controllers ... >> Modify Permissions ...
      (microsoft.public.windows.server.security)