[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 192
  • Last Modified:

Access Rights

Experts,

We have AD forest with a child domain. I'm one of the Admins and we are planning to hire 2 junior admins. I would like them to have limited access rights on the system. all i want them to do is add PCs to the domain, install apps on PCs etc. Nothing inside the servers. What is the best way to do this?

Also I would like to add an enterprise admin to all the workstations using a Group policy. Can we do this?

Thank you.
0
Sajith Silva
Asked:
Sajith Silva
  • 2
1 Solution
 
Sarang TinguriaSr EngineerCommented:
Use restricted group as illustrated in below link for making enterprise admin
http://www.nixadmins.net/2009/10/21/using-restricted-groups-in-active-directory/

To allow Jr admins to install software on Client machine they should be local admins
Read below links on how delegate comman tasks to Jr Administrators

Active Directory rights delegation – overview « iSiek's blog about ...
http://kpytko.wordpress.com/2012/05/16/active-directory-rights-delegation-overview/

Active Directory rights delegation – part 2 « iSiek's blog about ...
http://kpytko.wordpress.com/2012/05/26/active-directory-rights-delegation-part-2/
0
 
Sajith SilvaAuthor Commented:
Thank you for all this. I did the first part of your answer but unfortunately it has not updated the local users inside the workstations. what could be the reason? i followed the exact steps.
0
 
Sajith SilvaAuthor Commented:
managed to fix it. i have created the GP in the different location.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now