Access Rights

Experts,

We have AD forest with a child domain. I'm one of the Admins and we are planning to hire 2 junior admins. I would like them to have limited access rights on the system. all i want them to do is add PCs to the domain, install apps on PCs etc. Nothing inside the servers. What is the best way to do this?

Also I would like to add an enterprise admin to all the workstations using a Group policy. Can we do this?

Thank you.
Sajith SilvaAsked:
Who is Participating?
 
Sarang TinguriaConnect With a Mentor Sr EngineerCommented:
Use restricted group as illustrated in below link for making enterprise admin
http://www.nixadmins.net/2009/10/21/using-restricted-groups-in-active-directory/

To allow Jr admins to install software on Client machine they should be local admins
Read below links on how delegate comman tasks to Jr Administrators

Active Directory rights delegation – overview « iSiek's blog about ...
http://kpytko.wordpress.com/2012/05/16/active-directory-rights-delegation-overview/

Active Directory rights delegation – part 2 « iSiek's blog about ...
http://kpytko.wordpress.com/2012/05/26/active-directory-rights-delegation-part-2/
0
 
Sajith SilvaAuthor Commented:
Thank you for all this. I did the first part of your answer but unfortunately it has not updated the local users inside the workstations. what could be the reason? i followed the exact steps.
0
 
Sajith SilvaAuthor Commented:
managed to fix it. i have created the GP in the different location.
0
All Courses

From novice to tech pro — start learning today.