Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Automate local admin rights when new user logs onto XP PC

Posted on 2007-03-24
4
Medium Priority
?
347 Views
Last Modified: 2012-05-05
Hi hope someone can help.

We are running SBS 2003 std.
PC's are all XP

Whenever I logon to a computer with a new user id the user doesn't have local rights to be able to change Power settings etc or install software. To get around this I use "Control Userpasswords2" and add the user manually as an Administrator for the PC.

I would like to automate this process so no matter which user logged onto the PC they would get local admin rights.

Thanks
0
Comment
Question by:deltacomputing
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 60 total points
ID: 18785293
I would be very cautious about giving everyone local admin rights, this should not be neccessary give users only the rights that they actually need.
0
 
LVL 11

Accepted Solution

by:
Zenith63 earned 240 total points
ID: 18785330
Add the domain group "Domain Users" to the local Administrators group on the PC.

Open Computer Management, expand the Local Users and Groups tree, open the Groups folder then double click on Administrators.  In the new window click Add... then type Domain Users and click OK.

Now any user who logs on to this PC and is a member of Domain Users(which all users are by default) will be local administrators on the PC.


Although having users as non-administrators is best in a large secure organisation, I find it's overkill and counter-productive in small companies where you tend to find SBS.  I'd always make users local admins of their PCs in an SBS environment.
0
 
LVL 5

Assisted Solution

by:reb_elmagnifico
reb_elmagnifico earned 225 total points
ID: 18785373
You can automate this using GPOs (assuming you are in an Active Directory domain).  Here is a good article:

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

Hope this helps.

Thanks

REB
0
 
LVL 1

Assisted Solution

by:andrewlee7
andrewlee7 earned 225 total points
ID: 18804524
You can create a batch file and use the command line:

net localgroup "Administrators" "MEMBERNAME" /add

You have to include the quotation marks.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question