Re: domain user with local admin right
- From: "Paul Bergson [MVP-DS]" <pbergson@xxxxxxxxxxxxxxxxx>
- Date: Thu, 24 Jul 2008 07:59:50 -0500
Sure, you can be a local admin on a workstation and yet not be a domain
admin and you are correct on choosing Restricted Groups to implement it.
To use the restricted user group gpo setting
computer configuration \ windows settings \ restricted groups
group = your group to be made local admins
member of = BUILTIN\Administrators
http://www.windowsecurity.com/articles/Using-Restricted-Groups.html
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechRef/156780ef-eb36-4433-b3fe-1b1a15c18f6a.mspx
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_scerestrictgroups.mspx
There is absolutely nothing that has to be done on the client side.
Create the gpo in the ou where the Computers reside (NOT the users), go to
computer configuration/windows settings/security settings/restricted groups,
right click on restricted groups and select new group (For the local
computers, this group name should be - administrators) and key in the group
you want auto populated. Select add on the Members of this group and then
add the members you want populated.
Note: Be aware that the higher you place this setting within the domains
group policy the possibility exists it is applied to machines you may not
want it applied to. With this in mind you should try and avoid this setting
at the domain level, with the exception on the domain admins group. We have
some users who are local admins on machines and for some reason they feel
compelled to remove the domain admins from their local administrators group.
Setting this at the domain level manages these annoying users.
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
"SeVilho" <sevilho7@xxxxxxxxxxx> wrote in message
news:esDhAZV7IHA.1592@xxxxxxxxxxxxxxxxxxxxxxx
Hi, all!
Is there possible to criate a domain user account which :
1. is a local administrator on target domain machines 2. have less rights
than Domain Admins
Is restricted group a property tool for it?
.
- References:
- domain user with local admin right
- From: SeVilho
- domain user with local admin right
- Prev by Date: Re: Fail ID 5723: Netlogon
- Next by Date: Re: creating a trust between windows 2000 and sbs 2000
- Previous by thread: Re: domain user with local admin right
- Next by thread: Re: domain user with local admin right
- Index(es):
Relevant Pages
|