Solved

How do I grant a group of uses the rights to install apps on their computers (Active Directory)

Posted on 2009-05-11
2
231 Views
Last Modified: 2012-08-13
I am simply looking for the proper way to allow a group of domain users (using Active Directory running on Windows Server 2003) the rights to install applications on their local PCs. Their elevated rights should only be local, I don't want to grant them any additional access to the network resources.

The majority of users do not have this privilege, which is as it should be, but I'd like to let some people install things without having to have me come do it for them.

Suggestions?
0
Comment
Question by:Sootah
2 Comments
 
LVL 18

Assisted Solution

by:flyingsky
flyingsky earned 200 total points
ID: 24358783
add that AD group into local admin group
0
 
LVL 15

Accepted Solution

by:
zelron22 earned 300 total points
ID: 24358883
It depends on whether or not it's okay for those users to have admin access on that group of machines, or whether you only want each user to have access on their own machine.

If you create an AD group, add all of these special users, and then add that group to each machine's local admin group, then they'll all have admin rights on each of those machines.  

Another option is to add them individually to their own machine's administrators group.

0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Join & Write a Comment

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now