What he's trying to do here [my read anyway] is automatically have everyone as local admin on their PCs from the get go. So that when they log into the domain, they will be admins on their system.

http://groups.google.com/group/microsoft.public.win2000.security/browse_frm/thread/9570ac134b07abff/60eb0461cf4af321?lnk=st&q=local+administrator+group+policy&rnum=8#60eb0461cf4af321

The gurus recommend setting up a new OU and leave your existing ones as is.

Now... that I've said you can, you do realize that your employees can now do everything and ANYTHING on their systems. Have an acceptable use policy in place to define what they can and cannot do.

Be prepared to get malware and have to flatten a machine or two or three.

Za Vue wrote:

Just tell everyone to log in using the default Administrator account and leave the password blank. Tell the users to change it later.
What company is this?

Is there any way to add "Authenticated Users" built-in group to the
local administrator group on every PC using restricted groups GPO?


Basically I want an easy way to make sure all users are local admins on
their PCs without creating a custom group.  Should I just use xxx\domain
users instead?



List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to