Re: Domain Rights

From: Tyler (Tyler_at_discussions.microsoft.com)
Date: 02/09/05


Date: Wed, 9 Feb 2005 08:05:04 -0800

If you use restricted groups to add the following users as local admins on
each PC you might run into problems.

Add:
Domain Admins
IT_Techs

By only adding those groups you will loose any other entries in the local
admin group. Such as if you have given each user local admin rights on their
machine those rights will go away.

Another way to do this is to create a GPO with a startup script that adds
your needed accounts/groups to the local admin group. This preserve your
current local admin group settings. This will require a new OU for your
client machines as you cannot apply a GPO to the default computers container.

"Burtsev Dmitry" wrote:

> Hello.
> I think this can help you.
> 1. Create a group for IT Techs and add necessary accounts
> 2. Create an OU for users. Move necessary groups to this OU (don't foget
> Domain Users!)
> Delegate for IT_techs group appopriate permissions (create, delete and
> manage user accounts, reset user passwords, modify the membership of group).
> Delegation of control wizard will help you.
> 3. Create a new OU for computers. Delegate permissions create/delete
> computer objects on this OU for IT Techs group.
> 4. Create Group policy object on computer OU. In this GPO define Restricted
> groups policy. Add IT_Techs to local administrators group. Don't foget
> about domain admins!
> About restricted groups you can read in this articles
>
> http://support.microsoft.com/default.aspx?scid=kb;en-us;279301
> http://support.microsoft.com/default.aspx?scid=kb;en-us;810076
>
>
> --
> Dmitry Burtsev [burtsev@removethis.km.ru]
>
>
>
> "Kevin" <Kevin@discussions.microsoft.com> wrote in message
> news:06a401c50eb4$28f93510$a401280a@phx.gbl...
> > I want to be able to take our IT Techs out of the Doamin
> > Admin Group but I need a way for these same user to do
> > Administrative tasks. Our enviroment consist of XP
> > stations and Server 2003 Domain Controller. The IT Techs
> > need to be able to add and remove computers from the
> > domain, reset passwords and if possible have full access
> > to the local XP stations (Loacl Admins on these boxes?)
> > ADMIN share for remote assistance and other administrative
> > functions. Is there a way to do this through Group Policy
> > or creatiing another OU and delegating some of these
> > abilities? Thanks in advance
>
>
>



Relevant Pages

  • Re: Domain Admins removed from local admin group
    ... You can use restricted groups to fix the administrators on the local machines. ... Even if the user is local admin and removes the domain admins after the next GPO refresh they will be in again. ...
    (microsoft.public.windows.server.general)
  • Re: local admin account password
    ... What I think would be a better scheme is to set a very complex* random ... This eliminates the vulnerability created by weak admin passwords ... Do you think if someone wanted to break the local admin account they ...
    (Focus-Microsoft)
  • Re: Opinions needed on Windows Administrative Rights
    ... >> CAN'T GIVE USERS ANY RIGHTS! ... Issuing local admin privs is dangerous because: ... A lot of new viruses first go after anti-viruses by stopping the process ...
    (comp.security.misc)
  • Re: How can I change the admin password of all our XP PCs on the doma
    ... You don't go to each workstation and check if that user changed the local admin password. ... If the box has a problem that means you can't use a domain admin account to logon, it is usually quicker to rebuild than troubleshoot. ... If you want to control the Local Administrators on the workstations, just disable the Local Administrator, and then use another GPO or Script that adds a existing security group in your AD as member of the local Administrators on the workstations. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Anonymous Web based printing for standard users
    ... local admin group, login and install the printeras the user, then remove ... them from the admin group. ... > which the printer is installed, either using IPP or RPC. ... > creates a local queue which requires local admin rights and with RPC it does ...
    (microsoft.public.inetserver.iis)