Solved

Domain Accounts

Posted on 2013-10-25
4
233 Views
Last Modified: 2013-10-25
Does anyone have a good website to define the different user accounts with active directory and their permission levels?

Also I want to add a new user and give him local administrative rights to all desktops within the domain but no admin rights to the domain itself currently.  What type of user would I need to configure?
0
Comment
Question by:mgerwelAF
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 6

Expert Comment

by:ButlerTechnology
ID: 39600144
I usually create a global group in AD called Workstation Admins.  The Workstation Admins group is a member of the Administrators group on each workstation.  You can leverage group policy's restricted group feature or preferences Local User and group to make this happen automatically.  I would recommend using the Preference option.

Tom
0
 

Author Comment

by:mgerwelAF
ID: 39600147
So would the users within the group 'Workstation Admins' be just regular users?
0
 
LVL 6

Accepted Solution

by:
vmdude earned 500 total points
ID: 39600164
Yes the users in the workstation admins group mentioned above would be just regular AD users. As long as the group is set to be Local Administrators on the computers (can be achieved via group policy) then thats all you need. No special AD permission required/
0
 

Author Closing Comment

by:mgerwelAF
ID: 39600189
Thanks for the info
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question