Re: User type



Mike

I miss-read you message - I now know that I must handle this in the startup
of the group - on the domain.

Thanks
"John Leonard - Sage" <sagegrp@xxxxxxxxxxxx> wrote in message
news:eosi1J0yFHA.720@xxxxxxxxxxxxxxxxxxxxxxx
> This does help Mike - thanks
>
> I still have to go to each workstation and add the BAT file to the
> startup.
>
> I was hoping to avoid that.
>
>
> "Miha Pihler [MVP]" <mihap-news@xxxxxxxxxxx> wrote in message
> news:OrOSjoJyFHA.3624@xxxxxxxxxxxxxxxxxxxxxxx
>> If the computer is member of domain then you should use domain user
>> accounts. You could create new domain user account that is not member of
>> Domain Administrators group (actually you only leave it in default
>> group -- Domain User). Add this computer account to new domain group
>> called e.g. "Local Admins"
>>
>> After you have this account and group created you can write a short
>> script that will add "Local Admins" group to the "Administrators" group
>> in local administrator and make your users local administrators. The
>> script can be something like this:
>>
>> net localgroup administrators "Domain\Local Admins" /add
>>
>> Replace Domain with netbios name of domain where and Local_Admins is
>> domain group where your users who need to be local admins are located.
>> Put above command in batch file and run it as startup script (not logon
>> script) using your Active Directory. This way you don't have to go from
>> computer to computer to make changes to your PCs. After restart of your
>> domain computers above script will run and add domain group to local
>> Administrators group and your users will have administrative permissions
>> on every computer in domain where script run.
>>
>> I hope this helps,
>>
>> --
>> Mike
>> Microsoft MVP - Windows Security
>>
>>
>> "John Leonard - Sage" <sagegrp@xxxxxxxxxxxx> wrote in message
>> news:ecqnBbtwFHA.1028@xxxxxxxxxxxxxxxxxxxxxxx
>>>I want them to authenticate from a client computer (local) and have admin
>>>rights on that.
>>>
>>> They have romaing profiles.
>>>
>>>
>>> "Miha Pihler [MVP]" <mihap-news@xxxxxxxxxxx> wrote in message
>>> news:OkTmex6vFHA.3300@xxxxxxxxxxxxxxxxxxxxxxx
>>>> OK lets go back a bit. Where would you like them to be Administrators
>>>> (e.g. on their own PCs) and what tasks do they need to perform.
>>>>
>>>> --
>>>> Mike
>>>> Microsoft MVP - Windows Security
>>>>
>>>>
>>>> "John Leonard - Sage" <sagegrp@xxxxxxxxxxxx> wrote in message
>>>> news:OCuz7E4vFHA.1716@xxxxxxxxxxxxxxxxxxxxxxx
>>>>> Ok - I'm confused.
>>>>>
>>>>> Are you telling me to create the Local_Admins folder on the domain (as
>>>>> a domain group) under active directory and then go to each computer
>>>>> aand add the startup command line to the local policy?
>>>>>
>>>>> or
>>>>>
>>>>> Do I do it all on the local computer/client?
>>>>>
>>>>> I was hoping for a simple - one step for all- solution. I am
>>>>> constantly changing the users in this group.
>>>>>
>>>>> thx
>>>>> "Miha Pihler [MVP]" <mihap-news@xxxxxxxxxxx> wrote in message
>>>>> news:%23DWLxbDnFHA.3256@xxxxxxxxxxxxxxxxxxxxxxx
>>>>>> Hi,
>>>>>>
>>>>>> If you would like to make a group of users only local administrators
>>>>>> on the computers in e.g. domain then add domain group with these
>>>>>> yours that you created to Local Administrators group on the
>>>>>> computers. You can do it manually or using script
>>>>>>
>>>>>> The way I usually do it is by using a script like this
>>>>>>
>>>>>> net localgroup administrators "Domain\Local_Admins" /add
>>>>>>
>>>>>> Replace Domain with netbios name of domain where and Local_Admins is
>>>>>> domain group where your users who need to be local admins are
>>>>>> located.
>>>>>> Put above command in batch file and run it as startup script (not
>>>>>> logon script).
>>>>>>
>>>>>> This will make members of Local_Admins group local administrators on
>>>>>> the computers where script will run, while they won't be domain
>>>>>> administrators.
>>>>>>
>>>>>> I hope it helps you out,
>>>>>>
>>>>>> --
>>>>>> Mike
>>>>>> Microsoft MVP - Windows Security
>>>>>>
>>>>>>
>>>>>> "John Leonard - Sage" <sagegrp@xxxxxxxxxxxx> wrote in message
>>>>>> news:OG93AtBnFHA.3448@xxxxxxxxxxxxxxxxxxxxxxx
>>>>>>> How do I setup a group of users, to be administrators, without
>>>>>>> adding them to the Domanin Admin group?
>>>>>>>
>>>>>>
>>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>
>


.



Relevant Pages

  • Re: User type
    ... Domain Administrators group (actually you only leave it in default group -- ... Add this computer account to new domain group called e.g. ... After you have this account and group created you can write a short script ... group where your users who need to be local admins are located. ...
    (microsoft.public.windows.server.setup)
  • Re: Membership...
    ... I would like to remove DOMAIN account from a LOCAL administrators group REMOTELY using vb script. ... The following script can remove the member of the Administrators group if the account is a LOCAL account to that computer. ... If the account is a DOMAIN account, I got the error with message: 'A member could not be added or removed from the local group because the member does not exist'. ...
    (microsoft.public.scripting.vbscript)
  • Re: Creating a One Time Use Account
    ... The best I could think of is a script that checks a value in the registry ... following day when you enable the account and hand out a password. ... different ways to attack it depending on your specific needs. ... they log out a new key will be generated and network administrators will ...
    (microsoft.public.windows.server.active_directory)
  • Re: User type
    ... Do I put the script, using gpedit.msc, on the domain or workstations. ... > If the computer is member of domain then you should use domain user ... Add this computer account to new domain group called e.g. ... > administrator and make your users local administrators. ...
    (microsoft.public.windows.server.setup)
  • Re: Startup Script
    ... to a remote system on startup. ... added the vbs script to run at startup; ... The script works fine if I double-click the file within Windows; ... Drive mappings are only meaningful in the context of the account that does ...
    (microsoft.public.scripting.vbscript)