Solved

Allowing users local administrative rights

Posted on 2007-03-29
9
213 Views
Last Modified: 2010-04-20
Hi Fellow Geeks !
Can anyone tell me how OR point me to a step by step guide on how to do the following.
I have a Win 2003 standard server running as DC...2x desktop PC's & 4 laptops. One user needs to have admin access when logging on to some computers EXCEPT DC.. How can I acheive this ??
Thanks in advance !!
John
0
Comment
Question by:mrmad1966
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 2

Expert Comment

by:emiops
ID: 18817879
promote his AD account on each computer (since you dont have that many to manage) to local administrator.

Control panel, user accounts, then find his AD account on the domain.

0
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 18817904
Bad idea, putting his account in the local admin group on all machines.  This is a nightmare to manage.

If you MUST make him a local admin (NEVER a good idea, but there are some poorly written software programs that require it), then create a group in Active Directory - something called "Local Admins" or something like it - then put the user in that group.  Go to each workstation and put the "local admins" group into the local "Administrators" group.  By doing this is becomes VERY easy to remove the user from the local admins on all workstations and likewise, very easy to add another user if you need to.
0
 
LVL 2

Expert Comment

by:emiops
ID: 18817972
suppose you can do that too... same result... easier to manage

Keep in mind that it is problably better for that user to have atleast 2 AD accounts.  One for normal use, and the other to use only when he needs Admin rights (to install applications and so on) so he isnt always on as a local admin when he doesnt need to be.
0
 
LVL 1

Author Comment

by:mrmad1966
ID: 18818325
Hi all..
leew's answer does do the job, but if my network were larger or geographicaly different, is there no other option than edit the local Users Group on each workstation...??? Thanks
0
Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

 
LVL 4

Expert Comment

by:vnicolae
ID: 18818349
You can create a GPO that adds a user to the local administrators group. It all depends on what you want to do exactly. What rights do you want this super-user to have?
0
 
LVL 1

Author Comment

by:mrmad1966
ID: 18818442
I'd like him to be able to install software..But obviously NOT on the DC. I do not want him to be able to log on locally to the DC!
0
 
LVL 4

Expert Comment

by:vnicolae
ID: 18818519
If you want them to install software, you have to give them local administrator rights. Either add them manually to the local group or via GPO.
0
 
LVL 2

Expert Comment

by:emiops
ID: 18818571
I am not sure how to use GPO to do what vnicolae is saying, but

If you create multiple GPO's that correspond with the different OU's in AD you can push GPO Updates to your computers while skipping your DC.

But for a 6 computer domain... Might just be easier to do what me or leew said at the beginning.
0
 
LVL 48

Accepted Solution

by:
Jay_Jay70 earned 500 total points
ID: 18820423
mrmad1966,

I understand the predicament here and have seen it many time due to crappy software - though its been made a little to complex...

Restricted groups will take care of membership
http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

As far as the DC side of things goes - edit the default domain controllers policy - computer config - windows settings - security settings - user rights assignment - allow logon locally...just add your Administrator and any other explicit allows.

Regards,

James
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now