Solved

What is the easiest way to add/remove a domain user to the local admin group of a workstation?

Posted on 2007-11-30
8
339 Views
Last Modified: 2010-04-21
Once in a while, I need to give temporarily some domain user local admin privilege of a specific workstation. For ease of discussion, I make up some names here.

Windows 2003 server AD: svr-dc
domain user: userA
workstation (XP): pc-user
workstation (XP): pc-admin
Goal: look for some quick way (maybe script) to add/remove userA to/from the local admin group of pc-user.

Q#1. Is it possible to run some script (on demand) to achieve the above goal?
Q#2. Is there any other way (maybe better) to do this?

Thanks.
0
Comment
Question by:richtree
8 Comments
 
LVL 51

Accepted Solution

by:
Netman66 earned 320 total points
ID: 20384681
If you run COMPMGMT.msc as your domain admin account you can remote connect using Manage>Connect to Computer.

From here you can remove/add users to the local Admin group.
0
 

Author Comment

by:richtree
ID: 20384726
Yes, that works.
Any other way?
0
 
LVL 51

Assisted Solution

by:Netman66
Netman66 earned 320 total points
ID: 20384768
Restricted Groups - but that's overkill.

you can run psexec to remotely run net group Administrators {username} /Add

0
 
LVL 30

Assisted Solution

by:LauraEHunterMVP
LauraEHunterMVP earned 100 total points
ID: 20384807
Download lg.exe from www.joeware.net/freetools.

lg.exe \\workstation\Administrators domain\jsmith -add

Assuming you are running the command with an account that has administrative rights to the remote w/s, works like a champ.
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 21

Assisted Solution

by:mastoo
mastoo earned 30 total points
ID: 20384815
NET LOCALGROUP Administrators name1 /ADD
0
 
LVL 3

Assisted Solution

by:chokdii
chokdii earned 50 total points
ID: 20384837
Hi,

If you want to script this into a batch file or similar script file, I would suggest using WMIC with usual DSADD command set.
I have not personally used it this way, but I am sure it can be easily done.

To invoke WMIC, just type that in the cmd prompt in a Domain admin account.
0
 
LVL 51

Assisted Solution

by:Netman66
Netman66 earned 320 total points
ID: 20384849
Oops, yes - I'm on a DC!

net localgroup Administrators {username} /Add

lg.exe is Joe's version of Net, is it not?


0
 

Author Closing Comment

by:richtree
ID: 31412011
Thank you all for your wonderful ideas.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now