Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 305
  • Last Modified:

local admins group policy

i am using 2003 server to make domain users local admins on all computers. i am using the group policy managent with the restricted groups in security settings restricted groups. my problem is that when i select "domain computers" to apply to. it puts domains users  in my administrators group in active directory. making it an issue b/c then everyone can c everything administrators can. i have thought about making another group and putting all computers in that. or an ou and moving computer from the computers folder to the ou however i thought that might cause some problems. just thought i would ask the best way to accomplish this. the domain controller is not in the domain computers group however so i am not sure how it is applying. thanks in advance.
1 Solution
First of all, don't add Domain Users to the local Administrators group.

If you have badly-written software that won't run under an ordinary user account, use Process Monitor to determine what files and registry keys it is trying to access.  Grant users permission to access those specific files and keys.

If that doesn't work and you absolutely must make users administrators on workstations, then add the local INTERACTIVE account to the local Administrators group.  This will give administrative privileges to the user who is interactively logged onto a workstation, but will not give them those rights to other machines over the network.
ThinkPaperIT ConsultantCommented:
any specific reason why you need to make users local admins on the workstations?

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now