Avatar of c7c4c7
c7c4c7Flag for United States of America

asked on 

Server 2016 how do I allow users to load programs on their own Workstations

The server is running Server 2016

Some of the users need to be able to load software on their own machines, I know this is not ideal.

There is a segment of the users that need to be able to evaluate software, the company is willing to accept the risk of allowing them to load software.  The company does not want them all to be Domain admins, I'm assuming that there is a security policy somewhere that can be configured to allow the select few to load software on their machines.  But I don't know how to do it.

They are all admins on their own local machines

Thanks for the help
Active DirectoryWindows 10AzureWindows Server 2016

Avatar of undefined
Last Comment
McKnife
ASKER CERTIFIED SOLUTION
Avatar of Peter Hutchison
Peter Hutchison
Flag of United Kingdom of Great Britain and Northern Ireland image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of Lee W, MVP
Lee W, MVP
Flag of United States of America image

They are all admins on their own local machines
So then they ALREADY HAVE the ability to install software!

What's not working / why do you think it's not working?  What are the error messages you're getting.

BTW, the SMART way to do this is to REMOVE them from being administrators on their local machines - then give them a SEPARATE LOCAL ACCOUNT that has local admin rights.  NO USER ANYWHERE should be running with admin privileges.  They should be forced to enter a local admins account to perform administrative tasks.  That's SMART security while providing reasonable access to what they need!
Avatar of yo_bee
yo_bee
Flag of United States of America image

I would recommend that you setup some Isolated network for these users and give them a separate computer to work on.    This is a pretty dangerous  risk for your employer to take. The monetary cost to get these users the hardware needed is worth the value of the data if it is lost  data.

I would get something in writing dissolving yourself of any risk.
Avatar of c7c4c7
c7c4c7
Flag of United States of America image

ASKER

Just what I asked for, thanks for the help
Avatar of McKnife
McKnife
Flag of Germany image

You'll leave some people puzzled if you accept a solution to a problem (need privileges to install software) that you shouldn't even have ("They are all admins on their own local machines") - Any admin may install software.
Active Directory
Active Directory

Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.

86K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo