Re: AD to desktop Permissions problem



On Mar 19, 2:27 pm, chris.f...@xxxxxxxxx wrote:
On Mar 19, 10:40 am, "Laura E. Hunter [MVP]"

<laurahcomputing.nos...@xxxxxxxxx> wrote:
Let's begin straight off with this: you can add the fac member's domain
account to the local administrators group on her workstation without making
her a Domain Admin. The former proffers admin rights to a single
workstation, the latter to your entire domain. I would sooner set my hair on
fire than make a user a DA to address a local application problem; it's a
horrific idea and one that should not have been implemented even as a
temporary workaround.

To troubleshoot the individual application issues, you can use filemon and
regmon to determine which files and registry keys the user is unable to
access as a Standard User. These tools are available as a free download
here:http://www.microsoft.com/technet/sysinternals/default.mspx



This solution worked like a champ! Thank you.

.



Relevant Pages

  • Re: AD to desktop Permissions problem
    ... account to the local administrators group on her workstation without making ... her a Domain Admin. ... The former proffers admin rights to a single ... workstation, the latter to your entire domain. ...
    (microsoft.public.windows.server.general)
  • Re: How to grant security access to Help Desk?
    ... Add it tot he Local Administrators group. ... I finally got approved to get some help and hired a help desk engineer. ... don't want to give him "domain Admin" security access. ... the workstation. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help me
    ... Could you tell me how to set "workstation has domain administrators (for old ... > Try logging on to your new ADS machine as a domain admin for the old ... > domain) as a member of local administrators group. ...
    (microsoft.public.windows.server.migration)
  • Re: Win2k User Management
    ... Being a domain admin imparts no special powers over workstations. ... If the workstation owner has removed domain admins ... from the local administrators group, the domain admins have no direct rights over the workstation, they could if they ...
    (microsoft.public.win2000.security)
  • Re: users must be local admin but this means domain admin can be locked out
    ... and audit all workstation group membership from the domain instead of having ... > If you delete the domain admin from the machine, domain admin can login, ... Can modify the users and groups *that they have created.* ... operating system services or modify operating system files ...
    (microsoft.public.win2000.security)