Solved

SBS2011 Domain Profile user rights on Server and Workstation

Posted on 2014-03-19
6
795 Views
Last Modified: 2014-04-01
I have a SBS2011 and Win 7 Pro 64 bit workstations. We have a shared folder and "everyone" has full control. Is this automatically all users? Can I look at this group? I do not see it listed.

We are having an issue with timeslips 2014.  WE are being told that is has something to do with user permission levels. My questions are about user permissions, workstations rights and domain profile rights.  

Question:

If I install a new workstation and login with the existing domain profile...how does that effect the users rights on the workstation. I ask because the user was not really created as a user first and then added to the domain.  How do I ensure that user has administrative rights at the workstation?

2nd question

The client does not want the "users" to have administrative rights. Is "power user" the way to go or leave the users at just "users". I want to grant as much acess as possible with out allowing the use to delete system files. I also want the user profile to be able to install software on their workstations.

Thank you
0
Comment
Question by:Joemt
  • 3
  • 3
6 Comments
 
LVL 10

Expert Comment

by:Schuyler Dorsey
Comment Utility
1. A user's rights depends on the local administrator group settings of the workstation. E.g. if the A.D. group Domain Admins is listed in a workstation's Local Admins group, then a new user in the group, Domain Admins would automatically become a local admin.

Assuming it is a standard user and NOT a part of Domain Admins, you can add them to local admins rather easily. Login to that workstation as an admin, open Command Prompt with elevated privs and use the command:

net localgroup administrators user /add
e.g. net localgroup administrators jdoe /add  - would add user JDoe to the local admins of that workstations.

2. The closest you may be able to get is Power Users. Though I must ask why you want them to be able to install software if the client does NOT want them to be local admins?

You could also keep them as standard users and adjust UAC settings with Group Policy.
0
 

Author Comment

by:Joemt
Comment Utility
We want the users to have limited rights on the server and admin rights on there workstations or at least able to load software if necessary.

If the user did not have admin rights on the local workstation, then I need the local workstation to prompt me for a user with administrator rights.
0
 
LVL 10

Accepted Solution

by:
Schuyler Dorsey earned 500 total points
Comment Utility
I would advise making them a standard user and keeping UAC enabled.

With UAC enabled, when a user goes to install an application, it will prompt for account credentials with administrative rights to that workstation.

Note that rights to the workstations and rights to the server are separate.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 

Author Comment

by:Joemt
Comment Utility
Could you please explain this a little more:

"You could also keep them as standard users and adjust UAC settings with Group Policy"
0
 
LVL 10

Expert Comment

by:Schuyler Dorsey
Comment Utility
You can control UAC behavior via Group Policy.
http://technet.microsoft.com/en-us/library/dd835564(WS.10).aspx

However, if you want it to prompt for administrator creds when they try to install something, I would not change anything. Prompting is the default action for UAC.
0
 

Author Comment

by:Joemt
Comment Utility
When it prompts for administrator creds...is that administrator a local admin or server admin?
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

So many times I have seen the words written in a question "if only I could show you" or " I know how hard it is for you since you can't see it" in any zone. That has inspired me to write about this tool in windows 7 called "Problem Steps Recorder…
Article by: Lee
Windows 7 Ultimate and Enterprise (and 2008 R2) introduced a new feature you may not be aware of - Boot from VHD.   Boot from VHD (or what Microsoft refers to asNative Boot allows you to install Windows to a VHD (Virtual Hard Disk) file that is t…
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now