Solved

Add user to Local admin group in windows XP & 2003

Posted on 2008-11-03
4
1,483 Views
Last Modified: 2012-05-05
Dear All,

I need to add one user to all local administrator groups in all workstations in the network. I can do this by using Restriction Group in group policy, but this will make a problem because it will delete all users inside the local administrator groups and put the one whos add in the restriction group.
I need to add one user without affecting the users membership in the local administrator group.

Please help me.
0
Comment
Question by:devdept
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 11

Expert Comment

by:theProfessa
ID: 22867298
0
 
LVL 13

Expert Comment

by:dhoffman_98
ID: 22867312
You can do this by using the "Member Of" function of the Restricted Group policy instead of using the "Members" function. The Members function will overwrite the existing settings. The Member Of function merges your change into the existing settings.

Create a group. Add the user to the group.
Create a policy using Restricted Groups, and select the group you created. Then in the bottom part of the next window, enter "Administrators" where it asks for "This group is a member of".

Note that you can not simply use the user object. You will need to put them into a group first, even if they are the only object in the group.

For more information: http://support.microsoft.com/kb/810076
0
 

Author Comment

by:devdept
ID: 22868911
Do i can use any script that can add users to the local group? if yes, does anyone can provide me this script
 
 
 
0
 
LVL 13

Accepted Solution

by:
dhoffman_98 earned 500 total points
ID: 22872120
You  can use the script in the link that "theProfessa" showed above. But if you have an AD environment already, then why not use the tools already built into AD? You were on the right track when you tried it the first time, you only made the mistake of using the wrong setting so that it would replace the existing settings instead of merging the changes.

Read the KB article and follow my suggestions and you will automatically have what you want without having to write scripts.

0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question