Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Add non domain admins as local admins to workstations via GP

Posted on 2004-11-04
7
Medium Priority
?
195 Views
Last Modified: 2010-04-19

I have been struggling with this one. How can you, by Group Policy, add a certain global group as administrators to local machines. I have a desktop guy who's not ready to be a domain administrator yet I would like him to add/remove workstations to the domain and create user accounts and such. Anybody have a efficient method of achieving this? I read somewhere on EE that this was possible by using 'Restricted Groups' under computer configuration but when I looked there it wasn't very intuitive!
0
Comment
Question by:SANG501
  • 3
  • 3
7 Comments
 
LVL 20

Accepted Solution

by:
What90 earned 600 total points
ID: 12499949
Hi SANG501,

Restricted Groups works very nicely for what your trying to do. See if these link help out settin it up:

http://www.computerperformance.co.uk/w2k3/gp/group_policy_security_restricted_group.htm
http://support.microsoft.com/kb/q279301

Then, I'd delegate some permissions in AD for an OU or two for him to add/delete workstaions, create accounts and change their details.

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/ctrlwiz.mspx
0
 
LVL 11

Assisted Solution

by:WeHe
WeHe earned 600 total points
ID: 12499998
to give someone rights for adding and creating users/computers in ad, you can use the "delegation of control" wizard, built into the AD Users & Computers.
the problem with restricted groups is, that all other members of this group will be removed.
we solved such a task with a startup script and adding our support group with "net localgroup" to the local administrators group.
0
 
LVL 1

Author Comment

by:SANG501
ID: 12506181

Ok so if I added domain admins and user "Kenny" to the Restirced group policy and applied to to my workstation OU, will this over write any members in the 'local administrators' group excluding the local administrator itself?

Our OU structure
-domain.local
 -Corporate Headquarters
  -Servers
  -Users
  -Workstations (Should the restircted group policy be applied here or the domain policy?)

0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 11

Expert Comment

by:WeHe
ID: 12506335
yes, it will override your local group!
i would assign it in an extra policy to your workstation ou only.
0
 
LVL 1

Author Comment

by:SANG501
ID: 12508596
Works great! Question, what wil be the best method to apply this to all workstations except "administrator" workstations? This will be my last question before I award points. Thanks!!!!
0
 
LVL 11

Expert Comment

by:WeHe
ID: 12508660
- put all admin workstations into a own ou.
or
- add "security filtering" to your gpo.
or
- build a WMI FIlter.

i would prefer the ou, but security filtering is a good solution too.
0
 
LVL 1

Author Comment

by:SANG501
ID: 12508947
Thank you guys so much!
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Loops Section Overview
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question