Solved

Access Rights

Posted on 2013-01-23
3
189 Views
Last Modified: 2013-02-01
Experts,

We have AD forest with a child domain. I'm one of the Admins and we are planning to hire 2 junior admins. I would like them to have limited access rights on the system. all i want them to do is add PCs to the domain, install apps on PCs etc. Nothing inside the servers. What is the best way to do this?

Also I would like to add an enterprise admin to all the workstations using a Group policy. Can we do this?

Thank you.
0
Comment
Question by:Sajith Silva
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 18

Accepted Solution

by:
Sarang Tinguria earned 500 total points
ID: 38811004
Use restricted group as illustrated in below link for making enterprise admin
http://www.nixadmins.net/2009/10/21/using-restricted-groups-in-active-directory/

To allow Jr admins to install software on Client machine they should be local admins
Read below links on how delegate comman tasks to Jr Administrators

Active Directory rights delegation – overview « iSiek's blog about ...
http://kpytko.wordpress.com/2012/05/16/active-directory-rights-delegation-overview/

Active Directory rights delegation – part 2 « iSiek's blog about ...
http://kpytko.wordpress.com/2012/05/26/active-directory-rights-delegation-part-2/
0
 

Author Comment

by:Sajith Silva
ID: 38839765
Thank you for all this. I did the first part of your answer but unfortunately it has not updated the local users inside the workstations. what could be the reason? i followed the exact steps.
0
 

Author Comment

by:Sajith Silva
ID: 38843646
managed to fix it. i have created the GP in the different location.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are many software programs on offer that will claim to magically speed up your computer. The best advice I can give you is to avoid them like the plague, because they will often cause far more problems than they solve. Try some of these "do it…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question