Re: Best way to give local admin rights only across the domain



restricted groups feature in a GPO --> allows you to add a group/user to local groups on clients/servers if those fall under the scope of management of the GPO with that configuration

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test ANY suggestion in a test environment before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------

"compu" <Compustudent@xxxxxxxxx> wrote in message news:a0b5eaf9-f0c2-40d6-a225-c3792a13c878@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
What is the best way to give a user admin rights on any workstation
they will login to but not admin rights on the domain?

I am thinking about putting them in group administrators, but I am
afraid that will give them admin rights on the domain.



Thank you

.



Relevant Pages

  • Thanks Jorge de Almeida Pinto
    ... template with the registry setting, load it into a GPO, link the GPO to a ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ... "Log on using dial-up connection" with in group policy settings. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Undo Account Lockout Policy GPO
    ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ... I changed this GPO 24 hrs before I tested. ... If you could tell me how to reverse to the old values, ...
    (microsoft.public.windows.server.active_directory)
  • Re: disable/remove "Log on using dial-up connection" on logon window
    ... if there is not default setting available in a GPO, create your own ADM template with the registry setting, load it into a GPO, link the GPO to a OU, et voila! ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ... How can disable all users on OU in Active Directory to select "Log on using dial-up connection" with in group policy settings. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Undo Account Lockout Policy GPO
    ... Tattooing is similar to if you were to go up to a machine and run your ... Now if you were to go into your gpo ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admin?
    ... domain admins group is too much! ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ... but I don't want them to have admin rights on the server. ...
    (microsoft.public.windows.server.active_directory)

Quantcast