Link to home
Start Free TrialLog in
Avatar of Tonygret
TonygretFlag for United States of America

asked on

What AD account for temporarty admin

I have to create an account for a third party to be able to load software on some of our desktops locally, but I do not want them to access the domain controllers.  What group shoud I put them in?  I am running Win2003 Server standard SP2.  
ASKER CERTIFIED SOLUTION
Avatar of Mike Kline
Mike Kline
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Put them in the Local Administraotrs Group on the Workstations. (not the Domain Admin groups)
Avatar of Tonygret

ASKER

hanccocka,

I know that is an option, but I would have to create a local account on dozens of PCs.  That is what I am trying to avoid.
No you don't just create an AD account and group.  You add that group using a group policy (restricted groups)
You Create a Global AD Group. Add the Global Group to the Workstations Administrator Group.

Add the Account you Create to the Global Group.
hanccocka:,

I do not have a Workstation Admin Group.  Can you walk me through this process?  Thanks!
Create a new Global Group in Active Directory called Worlstation Admin Group?

Do you not know how to create users or groups using Active Directory Users and Computers?
hanccocka:

Yes I do know how, but creating a group does not restrict the user.
Correct, so you login to the workstation, and add the Worlstation Admin Group, to the Local Administrators group.
then when you add a AD user into the Worlstation Admin Group, they can Administer that Workstation ONLY.
OK, so I have to visit each workstaion anyway (or manager remoteley).  That is what I am trying to avoid.  
This can be done with Group Policy, are you proficient with Group Policies?
I have set up many Domains from the ground up with mulitple OUs and GPs. I know how o create OUs and GPs.  Howevre I am having a sort of mental block on this one.  I know how to assign permissions or make users a "Member Of" a group.  But there is no built in Workstation Admin group with the policies I need here.  I have no problem creating the group and adding the user, but how is it restricted?  Through a GP?   If so what setting in the GP need to be set or changed?
Mike in the first post, posted a url how to add tjis using group policy.
I did not see this link first time around.  That worked, thank you!