RE: adding domain users to power users

From: TH (TH_at_discussions.microsoft.com)
Date: 02/08/05


Date: Tue, 8 Feb 2005 13:53:08 -0800

Create a GPO that uses restricted groups. That is going to be the only way
you can do this quickly and easily. Using the Group Policy Management
Console, create a GPO, in the settings it is under Computer Configuration,
Windows Settings, Security Settings, Restricted Groups. Add a group (Power
Users) Then open that and add whoever you want to be power users on domain
computers. Save the GPO, and link it to your Computer OU or where ever your
computers are. I have done this multiple times in different enviroments and
have not had any problems.

"Al" wrote:

> We have to run an application in XP that only runs properly if the user is
> logged in locally on the computer and a member of the power users group. I
> would prefer that users first be logged into the domain. I can make this work
> by adding the domain users group to the power users group through the local
> user and groups management console on each computer. However this is a very
> time comsuming process when I have to do it on many computers. I've tried
> using restricted groups in the Group policy as indicated in other threads but
> it doesn't seem to work.
> Does anyone have any ideas.



Relevant Pages

  • Re: Setting local machine permissions via GPO
    ... > to see what it reports. ... > feature of Restricted Groups only works well if SP4 is installed. ... >>We need to set all our domain users up as power users on the local ... >>Now I can't get the gpo to set this permission on the local ...
    (microsoft.public.win2000.security)
  • Re: SCECLI event 1202 0x534
    ... Restricted Groups field when it prompts you for the group name. ... >>Create a null Power Users group in your Active ... >>> What exactly are you trying to do in the GPO... ... >>>> all the workstations. ...
    (microsoft.public.win2000.group_policy)
  • Re: Power User Setting Not Saved
    ... I've added the local user to the Power Users ... However Group Policy Restricted Groups ... can be used to manage membership of the power users group which seems to be ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Power Users
    ... use the Restricted Groups GPO. ... the Restricted Groups GPO you really need to do this from a workstations ... Active Directory Users and Computers MMC. ... remove everything that is a member of the local 'Power Users' group ...
    (microsoft.public.windows.server.active_directory)
  • Re: Power User Setting Not Saved
    ... There is no power users group in Active Directory - it is only available as ... However Group Policy Restricted Groups ... can be used to manage membership of the power users group which seems to be ...
    (microsoft.public.windowsxp.security_admin)

Loading