Solved

Dynamically adding domain account to local administrator group

Posted on 2004-04-08
5
1,829 Views
Last Modified: 2012-05-04
Does anyone know of a way to add a users domain account to the local administrator group on any machine that they log into on the domain.  We are trying to setup a way for users to login and have full rights to the computer that they login to without us having to add them to the local administrators group by hand.  Thanks for the help.
0
Comment
Question by:jsmall562
  • 3
  • 2
5 Comments
 
LVL 17

Expert Comment

by:RDAdams
ID: 10786696
Create a global group LocalAdmin ensure this group exists on each computer as administrator

example domain-x\LocalAdmin as a member on each computer in Administrator group

Add users who need local admin to this group as needed.  If they no longer need the access then remove them from the group.  
0
 
LVL 17

Expert Comment

by:RDAdams
ID: 10786703
You still need to add to each computer but this could be done via a script or batch file.
0
 

Author Comment

by:jsmall562
ID: 10786760
RDAdams - I appreciate the response.... I have already thought of doing that to be honest but like you said that will still require adding that group to each computer.  You are correct in that I could do that withy a script but unfortunately my scripting skills arent quite that good yet.  If you could give me an example of a script that would do this that would be very helpful.  Thanks for the help.
0
 
LVL 17

Accepted Solution

by:
RDAdams earned 125 total points
ID: 10786906
see http://www.myitforum.com/articles/11/view.asp?id=2457


Add Global Groups to Local Admin Group
 
By: Rod Trent
Posted On: 3/25/2002

Use this script to add global (domain) groups to the local Administrators group.

Modify the items in bold to your specific information.

Copy and paste the following script (between the lines) into Notepad, making sure to have Word Wrap disabled, then save it with a .vbs extension.

==================================
On Error Resume Next

'get main objects/variables
Set ws = WScript.CreateObject ( "WScript.Shell" )
compname = ws.ExpandEnvironmentStrings ( "%COMPUTERNAME%" )
Set adGrp = GetObject ( "WinNT://" & compname & "/Administrators,group" )

'add domain groups to local admin group
adGrp.Add ( "WinNT://domain/groupname,group" )
adGrp.Add ( "WinNT://domain/groupname,group" )

'handle errors
If (Err.Number <> 0) Then
strError = "AddAdmins.vbs was unable to add the specified groups to the local Administrators group."
strError = strError & vbCrLf & vbCrLf
strError = strError & "Error #: " & Err.Number & vbCrLf
strError = strError & "Source: " & Err.Source & vbCrLf
strError = strError & "Description: " & Err.Description & vbCrLf
ws.LogEvent 1, strError
Else
ws.LogEvent 0, "The local Administrators group was successfully updated."
End If
==================================

NOTE: Make sure you have the latest scripting engines on the workstation you run this script from. Download the latest scripting engines here: Microsoft Scripting Home Page
 
 
0
 

Author Comment

by:jsmall562
ID: 10787103
Thanks for the quick response!!  I appreciate the help, this should work out perfect.
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Viber-Only Restriction 6 43
MAC address learning of Riverbed 4 41
Fiber optic multimode cable issue 6 28
Cisco switch suggestion 5 46
Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question