Solved

newbie question on Domain permissions

Posted on 2009-07-07
4
197 Views
Last Modified: 2012-05-07
I have just added a new server to a company for the first time. Prior to this they were just using a workgroup. The server I installed is SBS 2008 and all of the computers are Vista 32 bit.
I can't figure out the computer permissions. Before I migrated I used the "Windows Easy Transfer" and backed up all of the user data. Then I used http://connect to add the computer to the domain. Then I used the "Easy Transfer" again to restore all of their files and settings.

Within SBS everybody is a standard user. Yet about half of the users have local admin rights on their PC's while the other half don't.
I have 2 questions:
1. How do I modify these "Standard Users" to lose their local admin rights?
2. What did i screw up to cause this in the first place?
0
Comment
Question by:LostInWindows
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 15

Accepted Solution

by:
HayesJupe earned 500 total points
ID: 24799206
you can set local admin via group policy, or manually - if you havent used group policy, the likely cause is that the "easy transfer" (which is really just the USMT) - has migrated the local admin group membership (something i only found out the other day it does and is not configurable - until usmt 4.0 comes out)
So, depending on the amount of machines were talking here, you can either go around and manually delete it, write yourself a startup script to do it, or use group policy
0
 
LVL 1

Author Comment

by:LostInWindows
ID: 24799246
I gather that Ican modify this locally on the computers? I assume that is is through Control Panel users, however, I don't think that Domain accounts show up here. How would I do this?
0
 
LVL 15

Expert Comment

by:HayesJupe
ID: 24799749
huh? you want to remove domain user accounts from local admin on the machines right?
Computer management | local users and groups | groups | administrators | remove the people you dont want in there.
0
 
LVL 1

Author Closing Comment

by:LostInWindows
ID: 31600866
Thanks!!
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
A hard and fast method for reducing Active Directory Administrators members.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question