Assigning Local Administrator Priviledges using Group Policy

AID: 9149
  • Status: Published

3510 points

  • Bydemazter
  • TypeTips/Tricks
  • Posted on2012-01-09 at 04:03:01

Introduction


You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies.

This article will demonstrate how to do this easily and how to manage which computers receive the policy.

Step 1 – Creating the Group Policy


Using the Group Policy Management Console(GPMC) we can create a Group Policy.  I like to give all my Group Policies a relevant name and prefix but you may have something different in your organisation.

I am going to call min PERM_ClientLocalAdminPermissions

The PERM allows me to quickly identify this policy as being related to permissions and then a descriptive name.

Launch the GPMC and locate the Group Policy Objects container.  Right Click and select New. Enter the policy name as shown below and click OK
 
RestrictedGroups-01.jpg
  • 18 KB
  • RestrictedGroups-01.jpg
RestrictedGroups-01.jpg

Once done, locate your policy in the list, right click and select Edit

Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Restricted Groups (as shown below)
 
RestrictedGroups-02.jpg
  • 88 KB
  • RestrictedGroups-02.jpg
RestrictedGroups-02.jpg

You now need to do the following:
  • Right Click on Restricted Groups and select Add Group
  • Click the Browse button
  • In the Enter the object names to select check box enter the name of the group you want to add to the local Administrators group
  • Click OK
  • In the This group is a member of dialog box click Add
  • Click Browse
  • Click Locations and ensure your local machine is selected
  • In the Enter the object names to select check box enter Administrators
  • Click OK and then OK again.


Step 2 – Assigning the Policy


It’s not possible to assign a Group Policy to the default computers container.  So you will either need to do this at the root Domain level, which I wouldn’t recommend because it would also be applied to servers (by default) or create a new Organisational Unit (OU), move all the computer objects in here and then assign the policy.

To create a new OU launch Active Directory Users and Computers, right click on the domain name at the top and select New and then OU.

Enter the name for your new OU and then click OK.

You can then move the computer objects from the default Computers container in to your new OU, either by dragging or dropping them, or by right clicking and selecting Move.

If you do not wish to apply this policy to all computers then only copy the computer object you want.

Once this has been completed we can link the new Group Policy we have created to the new OU.

To do this, using GPMC navigate to your new OU and right click on it.  Select Link an Existing GPO then locate your new Group Policy in the list and click OK.

Congratulations! You have now assigned a Group Policy to add all members of a Domain Group to the local Administrators group on all computers located in your new Organisational Unit.
    Asked On
    2012-01-09 at 04:03:01ID9149
    Tags

    AD

    ,

    GPO

    ,

    Local Admin Rights

    Topic

    Active Directory

    Views
    2141

    Comments

    Expert Comment

    by: younghv on 2012-01-09 at 05:28:43ID: 34355

    demazter -
    A very nice (and clean) set of instructions for this process. Thank you for publishing it.

    "Yes" vote above.

    Expert Comment

    by: alanhardisty on 2012-01-09 at 08:40:17ID: 34357

    Excellent article - If you were from Liverpool, I would have understand your choice of PERM for other reasons than the one you mentioned!

    Yes vote from me :)

    Add your Comment

    Please Sign up or Log in to comment on this article.

    Join Experts Exchange Today

    Gain Access to all our Tech Resources

    Get personalized answers

    Ask unlimited questions

    Access Proven Solutions

    Search 3.2 million solutions

    Read In-Depth How-To Guides

    1000+ articles, demos, & tips

    Watch Step by Step Tutorials

    Learn direct from top tech pros

    And Much More!

    Your complete tech resource

    See Plans and Pricing

    30-day free trial. Register in 60 seconds.

    Loading Advertisement...

    Top Active Directory Experts

    1. mkline71

      412,697

      Wizard

      3,000 points yesterday

      Profile
      Rank: Genius
    2. dariusg

      163,412

      Guru

      0 points yesterday

      Profile
      Rank: Genius
    3. dvt_localboy

      136,278

      Master

      0 points yesterday

      Profile
      Rank: Sage
    4. demazter

      116,263

      Master

      0 points yesterday

      Profile
      Rank: Genius
    5. iSiek

      113,702

      Master

      0 points yesterday

      Profile
      Rank: Genius
    6. motnahp00

      92,762

      Master

      0 points yesterday

      Profile
      Rank: Sage
    7. acbrown2010

      81,763

      Master

      10 points yesterday

      Profile
      Rank: Genius
    8. Jmoody10

      71,214

      Master

      1,210 points yesterday

      Profile
      Rank: Wizard
    9. yo_bee

      68,718

      Master

      0 points yesterday

      Profile
      Rank: Guru
    10. kevinhsieh

      60,310

      Master

      0 points yesterday

      Profile
      Rank: Genius
    11. KenMcF

      56,098

      Master

      0 points yesterday

      Profile
      Rank: Genius
    12. snusgubben

      55,438

      Master

      0 points yesterday

      Profile
      Rank: Sage
    13. pwindell

      54,060

      Master

      2,800 points yesterday

      Profile
      Rank: Genius
    14. KCTS

      52,196

      Master

      0 points yesterday

      Profile
      Rank: Genius
    15. leew

      51,399

      Master

      0 points yesterday

      Profile
      Rank: Savant
    16. PrashantGirennavar

      46,884

      3,000 points yesterday

      Profile
    17. Neilsr

      46,472

      0 points yesterday

      Profile
      Rank: Genius
    18. xxdcmast

      42,972

      1,100 points yesterday

      Profile
      Rank: Genius
    19. Anuroopsundd

      38,834

      0 points yesterday

      Profile
      Rank: Sage
    20. dstewartjr

      37,595

      0 points yesterday

      Profile
      Rank: Genius
    21. RobSampson

      36,382

      0 points yesterday

      Profile
      Rank: Genius
    22. ve3ofa

      34,856

      1,800 points yesterday

      Profile
      Rank: Genius
    23. amitkulshrestha

      34,647

      0 points yesterday

      Profile
      Rank: Genius
    24. alanhardisty

      32,393

      0 points yesterday

      Profile
      Rank: Genius
    25. McKnife

      32,203

      2,000 points yesterday

      Profile
      Rank: Genius

    Hall Of Fame