Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1587
  • Last Modified:

Adding 'Domain Users' to local Administrators group with Group Policy

Hello all,

We are replacing one of our client's old 2003 SBS servers with a 2011 SBS server.
We haven't used Group Policy much with any of our clients but I have decided that it'd be worth using to try and cut down the time it takes to setup the individual client machines.

I would like to add 'Domain Users' as local administrator on each machine, obviously not the server.

Is this possible?

Thanks in advance

Arran
0
systemagic
Asked:
systemagic
5 Solutions
 
Neil RussellTechnical Development LeadCommented:
0
 
Rob WilliamsCommented:
I agree restricted groups is the way to do so, but just a warning. If your admin account/s are in the wrong group it is very possible to lock your self out of all machines so review the policies carefully and be careful to whom you apply. The following is another article that may be of some help.
http://www.windowsecurity.com/articles/Using-Restricted-Groups.html
0
 
Rob WilliamsCommented:
By the way with SBS 2008/2011 you can also very easily do this form The Windows SBS console under users and groups | users | double click on the user | computers | make the user an admin of any machine you would like, and/or give them remote access to a PC.
0
New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

 
cbmmCommented:
another way of doing is by using psexec. this allows you to run a cmd remotely on each pc. you will have to download it. psexec \\computername cmd /c net localgroup administrators /add domain\userid
I use psexec alot, so i added it to the environment variables. Once you have the file extracted, browse to the directory via cmd prompt and run this.
psexec \\computername cmd /c net localgroup administrators /add domain\userid
0
 
cbmmCommented:
Here is another link using restricted groups. This is obvoiusly one of the best ways of doing this. Take a look here: http://www.windowsitpro.com/article/product-review/adding-a-global-group-to-the-local-administrators-group100759.aspx
0
 
systemagicAuthor Commented:
Thank you all very much. I have managed to implement this.
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now