Re: Local Computer Access In AD



"Lars Bengtsson" <LarsBengtsson@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0994FD68-7DAE-483A-B348-16E375D78A36@xxxxxxxxxxxxxxxx
So i have to assign the user to the power user group at the local
computer.
So if i have 200 computers and 400 users i would have to do that for each
one of them?


Not if you use the Restricted Group through a GPO method
I suggested earlier.

You can put "interactive" (group) in the Power Users this
way and only the person who actually logs on will be a
Power User of that machine.

But, Power Users is a specific set of privileges which
may be MORE or LESS than you really need.

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

"Herb Martin" wrote:

"Lars Bengtsson" <LarsBengtsson@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:F3D9A05E-34A3-450D-8FC1-087D6CE3EB37@xxxxxxxxxxxxxxxx
We have a few special programs here at the hospital.
Some people needs more access than standard user to their local
computers.
I Dont want to give these people admin access.

You need to first catalogue what specific privileges
are required, and who requires them (everyone may
not require the same privilege and Power User
may be either too much OR too little.)

How do I create a power user group that I can add users to and so it
applys
to all computer they access?

There is already a Power Users group on every
(non-DC) computer, which is granted some extra
privilege.

Until you know precisely what priveleges are required,
and by whom, you will not be able to intelligently and
safely allow the correct access.

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

"Herb Martin" wrote:

"Lars Bengtsson" <Lars Bengtsson@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:CC34B8DE-5560-4E8A-86BC-E528ED709C07@xxxxxxxxxxxxxxxx
How do I give domain users access to programs that are installed
with
the
administrator account?

Depends on the program. If the program requires no special
privileges then you merely move the shortcuts from the
Admin's profile to the All User's profile.

How do I give them access to install their orn programs?

In general, users can install their own programs. It is
actually VERY DIFFICULT to prevent this completely.

What specifically would you want them to run or install?
(It matters quite a bit.)

How do I make them a power user on the local computer?

Add the user to the Power Users group.

OR use a restricted group to add the "Interactive" group
to the Power Users group. Whoever can logon would be
a Power User.

Why do you need them to be power users?


--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]








.



Relevant Pages

  • Re: Allow user to run application as a power user
    ... > the system context that makes the current logged on user a member of the ... > Finally, after the application is complete, the script, under the system ... > Since we don't normally allow membership in the power users group, ...
    (microsoft.public.scripting.vbscript)
  • Re: All users printers showing up on terminal server
    ... This is not the case for you since your application will run okay with Power Users membership. ... A member of the Power Users group may be able to gain administrator rights and permissions in Windows Server 2003, Windows 2000, or Windows XP ... When the users log onto TS all the redirected printers are show on the ...
    (microsoft.public.windows.terminal_services)
  • RE: Power Users change?
    ... the rights and permissions that are granted to the Power Users ... members of the Power Users group to modify computer-wide settings, ... install drivers, and to run non-certified programs. ...
    (microsoft.public.windows.server.migration)
  • Re: Local Computer Access In AD
    ... You need to first catalogue what specific privileges ... users can install their own programs. ... Add the user to the Power Users group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local Computer Access In AD
    ... So i have to assign the user to the power user group at the local computer. ... You need to first catalogue what specific privileges ... Add the user to the Power Users group. ...
    (microsoft.public.windows.server.active_directory)