Allowing users local administrative rights

Hi Fellow Geeks !
Can anyone tell me how OR point me to a step by step guide on how to do the following.
I have a Win 2003 standard server running as DC...2x desktop PC's & 4 laptops. One user needs to have admin access when logging on to some computers EXCEPT DC.. How can I acheive this ??
Thanks in advance !!
John
LVL 1
mrmad1966Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

emiopsCommented:
promote his AD account on each computer (since you dont have that many to manage) to local administrator.

Control panel, user accounts, then find his AD account on the domain.

0
Lee W, MVPTechnology and Business Process AdvisorCommented:
Bad idea, putting his account in the local admin group on all machines.  This is a nightmare to manage.

If you MUST make him a local admin (NEVER a good idea, but there are some poorly written software programs that require it), then create a group in Active Directory - something called "Local Admins" or something like it - then put the user in that group.  Go to each workstation and put the "local admins" group into the local "Administrators" group.  By doing this is becomes VERY easy to remove the user from the local admins on all workstations and likewise, very easy to add another user if you need to.
0
emiopsCommented:
suppose you can do that too... same result... easier to manage

Keep in mind that it is problably better for that user to have atleast 2 AD accounts.  One for normal use, and the other to use only when he needs Admin rights (to install applications and so on) so he isnt always on as a local admin when he doesnt need to be.
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

mrmad1966Author Commented:
Hi all..
leew's answer does do the job, but if my network were larger or geographicaly different, is there no other option than edit the local Users Group on each workstation...??? Thanks
0
vnicolaeCommented:
You can create a GPO that adds a user to the local administrators group. It all depends on what you want to do exactly. What rights do you want this super-user to have?
0
mrmad1966Author Commented:
I'd like him to be able to install software..But obviously NOT on the DC. I do not want him to be able to log on locally to the DC!
0
vnicolaeCommented:
If you want them to install software, you have to give them local administrator rights. Either add them manually to the local group or via GPO.
0
emiopsCommented:
I am not sure how to use GPO to do what vnicolae is saying, but

If you create multiple GPO's that correspond with the different OU's in AD you can push GPO Updates to your computers while skipping your DC.

But for a 6 computer domain... Might just be easier to do what me or leew said at the beginning.
0
Jay_Jay70Commented:
mrmad1966,

I understand the predicament here and have seen it many time due to crappy software - though its been made a little to complex...

Restricted groups will take care of membership
http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

As far as the DC side of things goes - edit the default domain controllers policy - computer config - windows settings - security settings - user rights assignment - allow logon locally...just add your Administrator and any other explicit allows.

Regards,

James
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.