Group Policy for Local Admin rights

Hi All,
I would like to create a group policy (domain wide) for a manager that needs admin level access to domain servers on occasion. I am looking for a lower level of accessability then a domain admin, yet enable access.
Thanks for the help,
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Joseph MoodyBlogger and wearer of all hats.Commented:
You can use restricted groups to make this security group a member of the administrators group on the domain member servers.
tagltdAuthor Commented:
JMoody, thanks for quick reply. I am a bit foggy on your solution. Can you perhaps explain in greater detail. I would like to create this for only one single manager. Also, is there any real difference between local admin and domain admin?
Domain admin can administer domain controllers, configure GPO, DNS, create or delete domain users, etc., and you probably don't want it.

Create a domain local (or global if AD forest) group with computer accounts you want to target.

To deploy a new local admin to member servers, create a new GPO or modify an existing one using gpmc.msc, linked to an OU containing target computers.

Restrict this GPO to the group previously created (and remove authenticated users)

Modify this GPO and go to : Computer Configuration > Preferences > Control Panel Settings > Local User and Groups

Right-click and select New Local Group

Name Administrators (built-in), and add your manager account as member of this group.

A great article here :


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
tagltdAuthor Commented:
Outstanding solution! Thanks plenty for the detail and level.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.