Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Add user to Local admin group in windows XP & 2003

Posted on 2008-11-03
4
Medium Priority
?
1,495 Views
Last Modified: 2012-05-05
Dear All,

I need to add one user to all local administrator groups in all workstations in the network. I can do this by using Restriction Group in group policy, but this will make a problem because it will delete all users inside the local administrator groups and put the one whos add in the restriction group.
I need to add one user without affecting the users membership in the local administrator group.

Please help me.
0
Comment
Question by:devdept
  • 2
4 Comments
 
LVL 11

Expert Comment

by:theProfessa
ID: 22867298
0
 
LVL 13

Expert Comment

by:dhoffman_98
ID: 22867312
You can do this by using the "Member Of" function of the Restricted Group policy instead of using the "Members" function. The Members function will overwrite the existing settings. The Member Of function merges your change into the existing settings.

Create a group. Add the user to the group.
Create a policy using Restricted Groups, and select the group you created. Then in the bottom part of the next window, enter "Administrators" where it asks for "This group is a member of".

Note that you can not simply use the user object. You will need to put them into a group first, even if they are the only object in the group.

For more information: http://support.microsoft.com/kb/810076
0
 

Author Comment

by:devdept
ID: 22868911
Do i can use any script that can add users to the local group? if yes, does anyone can provide me this script
 
 
 
0
 
LVL 13

Accepted Solution

by:
dhoffman_98 earned 1500 total points
ID: 22872120
You  can use the script in the link that "theProfessa" showed above. But if you have an AD environment already, then why not use the tools already built into AD? You were on the right track when you tried it the first time, you only made the mistake of using the wrong setting so that it would replace the existing settings instead of merging the changes.

Read the KB article and follow my suggestions and you will automatically have what you want without having to write scripts.

0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
I’m willing to make a bet that your organization stores sensitive data in your Windows File Servers; files and folders that you really don’t want making it into the wrong hands.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

577 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question