?
Solved

How do I grant a group of uses the rights to install apps on their computers (Active Directory)

Posted on 2009-05-11
2
Medium Priority
?
276 Views
Last Modified: 2012-08-13
I am simply looking for the proper way to allow a group of domain users (using Active Directory running on Windows Server 2003) the rights to install applications on their local PCs. Their elevated rights should only be local, I don't want to grant them any additional access to the network resources.

The majority of users do not have this privilege, which is as it should be, but I'd like to let some people install things without having to have me come do it for them.

Suggestions?
0
Comment
Question by:Sootah
2 Comments
 
LVL 18

Assisted Solution

by:flyingsky
flyingsky earned 800 total points
ID: 24358783
add that AD group into local admin group
0
 
LVL 15

Accepted Solution

by:
zelron22 earned 1200 total points
ID: 24358883
It depends on whether or not it's okay for those users to have admin access on that group of machines, or whether you only want each user to have access on their own machine.

If you create an AD group, add all of these special users, and then add that group to each machine's local admin group, then they'll all have admin rights on each of those machines.  

Another option is to add them individually to their own machine's administrators group.

0

Featured Post

Restore individual SQL databases with ease

Veeam Explorer for Microsoft SQL Server delivers an easy-to-use, wizard-driven interface for restoring your databases from a backup. No expert SQL background required. Web interface provides a complete view of all available SQL databases to simplify the recovery of lost database

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

755 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question