Solved

Allow users to do updates on there PC

Posted on 2013-01-07
5
146 Views
Last Modified: 2013-01-08
I need to be able to allow users to do updates on there workstations & install software, I don't in anyway want to give them admin rights.
I'm thinking of a GPO that will give them power user rights, but I'm concern that it may be more permissions then what they need to just be able to do update and install software as needed. As it is the software will only be allowed to be installed if it's sign my MS.
Question,

In a GPO what would be the correct way of applying it, as in computers or users, where in the GPO do I do the editing ect....

Thanks
0
Comment
Question by:noad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 20

Expert Comment

by:netcmh
ID: 38753358
Ideally, it would be beneficial to everyone and more secure if you went the SCCM or any package distribution route. Access to the package can be controlled by AD.
0
 
LVL 20

Expert Comment

by:netcmh
ID: 38753359
If MS isn't the way you want to go, you have some options: http://www.golekupo.net/2011/07/system-center-configuration-manager-or.html
0
 
LVL 1

Author Comment

by:noad
ID: 38753372
Your idea regarding SCCM is a good one, except that it is $$$$ prohibited.
Any ideas alone the GPO?
0
 
LVL 11

Accepted Solution

by:
X_layer earned 500 total points
ID: 38756980
Here is link to complete article. I think you need to set this up:
Allow Non-administrators to Receive Update Notifications

This policy specifies whether logged-on non-administrative users will receive update notifications based on the configuration settings for Automatic Updates. If Automatic Updates is configured, by policy or locally, to notify the user either before downloading or only before installation, these notifications will be offered to any non-administrator who logs onto the computer.

If the status is set to Enabled, Automatic Updates will include non-administrators when determining which logged-on user should receive notification.

If the status is set to Disabled or Not Configured, Automatic Updates will notify only logged-on administrators.

To allow non-administrators to receive update notifications
In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.

In the details pane, click Allow non-administrators to receive update notifications, and set the option.

Click OK.
0
 
LVL 1

Author Comment

by:noad
ID: 38757046
X_layer

That's what I was looking for...
Thanks

Now if you could help me out with my other question I posted?

I need to be able to allow user to do update much in the same mange, hopefully using a GPO,but the updates would be for software install on the workstation such as java, flash, iTunes, adobe etc....
 See my other post and thanks for your help.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question