Adding 'Domain Users' to local Administrators group with Group Policy

Hello all,

We are replacing one of our client's old 2003 SBS servers with a 2011 SBS server.
We haven't used Group Policy much with any of our clients but I have decided that it'd be worth using to try and cut down the time it takes to setup the individual client machines.

I would like to add 'Domain Users' as local administrator on each machine, obviously not the server.

Is this possible?

Thanks in advance

Arran
LVL 1
systemagicAsked:
Who is Participating?
 
Neil RussellTechnical Development LeadCommented:
0
 
Rob WilliamsCommented:
I agree restricted groups is the way to do so, but just a warning. If your admin account/s are in the wrong group it is very possible to lock your self out of all machines so review the policies carefully and be careful to whom you apply. The following is another article that may be of some help.
http://www.windowsecurity.com/articles/Using-Restricted-Groups.html
0
 
Rob WilliamsCommented:
By the way with SBS 2008/2011 you can also very easily do this form The Windows SBS console under users and groups | users | double click on the user | computers | make the user an admin of any machine you would like, and/or give them remote access to a PC.
0
Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

 
cbmmCommented:
another way of doing is by using psexec. this allows you to run a cmd remotely on each pc. you will have to download it. psexec \\computername cmd /c net localgroup administrators /add domain\userid
I use psexec alot, so i added it to the environment variables. Once you have the file extracted, browse to the directory via cmd prompt and run this.
psexec \\computername cmd /c net localgroup administrators /add domain\userid
0
 
cbmmCommented:
Here is another link using restricted groups. This is obvoiusly one of the best ways of doing this. Take a look here: http://www.windowsitpro.com/article/product-review/adding-a-global-group-to-the-local-administrators-group100759.aspx
0
 
systemagicAuthor Commented:
Thank you all very much. I have managed to implement this.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.