Have you considered using restricted groups via group policy to put the
sub-administrators in one of the local groups on the servers? 

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Abbiss, Mark
Sent: Monday, January 24, 2005 7:22 AM
To: [email protected]
Subject: [ActiveDir] Controlling log on locally in an AD domain

I am having a real problem getting my head round setting the "log on
locally" policy for a group of computers.

What I am hoping to achieve is the ability to allow different groups of
sub-administrators the rights to log on locally to the servers they are
responsible for.

Currently, log on locally is only allowed to the Enterprise admins but
as the number of servers grows and we need to delegate responsibuility
to other nominated administrators, we find they are blocked from logging
on and we can't find a clean solution.

Can someone please point me in the direction of a tidy solution to the
problem.

Many thanks
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to