Now keep in mind that SBS's connection wizard does this for us and my manual memory 'how to' is a bit rusty....but I think the normal process includes creating an AD security group called "Workstation Admin", and add that group to the local admins group on each computer for existing machines. From the server... if you manage the computer & add it in the local users & groups . Then you can simply add users to the AD group as needed.

For existing deployed computers...this is our normal recommendation:


1)    On each PC, add the INTERACTIVE group to the Administrators group.
This will automatically give each user that logs in local Admin rights.
Downside is that if you ever want a user to not have local admin rights, you
won't be able to restrict them as long as you have this configuration.


2)    Create a Security Group within AD (e.g. Local Admins).  On each
workstation, add the domain Local Admins group you created to the local
Administrators group.  Then on your SBS, add your existing users to the
Local Admins group, and create a new user template that includes Local
Admins group membership.  When you create a new user, use the custom
template and they'll be included in the Local Admins security group, which
will give them local admin rights on the machines where you added the Local
Admins group to the local Administrators group.


3)    Preferred solution:  Don't give users local admin rights.  Find your
problem apps that don't run as a restricted user and start nagging the
vendor.  Ask why they find exposing your business to undue risk as a
justified business practice on their part. Find what directories / reg keys
those apps want access to and tweak the permissions accordingly to allow
restricted users to be able to access those locations (and thus run the
problem apps).




[EMAIL PROTECTED] wrote:

I'm splitting hair here, but .......

What you've recommended still doesn't achieve his stated goal - to make users
local admin rights on THEIR PCs.


Sincerely,

Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I
Microsoft MVP - Directory Services
www.readymaids.com - we know IT
www.akomolafe.com
Do you now realize that Today is the Tomorrow you were worried about
Yesterday?  -anon

________________________________

From: [EMAIL PROTECTED] on behalf of Susan Bradley, CPA aka
Ebitz - SBS Rocks [MVP]
Sent: Sat 10/29/2005 8:00 AM
To: [email protected]
Subject: Re: [ActiveDir] Restricted Groups question



What he's trying to do here [my read anyway] is automatically have
everyone as local admin on their PCs from the get go.  So that when they
log into the domain, they will be admins on their system.

http://groups.google.com/group/microsoft.public.win2000.security/browse_frm/t
hread/9570ac134b07abff/60eb0461cf4af321?lnk=st&q=local+administrator+group+po
licy&rnum=8#60eb0461cf4af321

The gurus recommend setting up a new OU and leave your existing ones as is.

Now... that I've said you can, you do realize that your employees can
now do everything and ANYTHING on their systems.

Have an acceptable use policy in place to define what they can and
cannot do.

Be prepared to get malware and have to flatten a machine or two or three.

Za Vue wrote:

Just tell everyone to log in using the default Administrator account
and leave the password blank. Tell the users to change it later.
What company is this?

Is there any way to add "Authenticated Users" built-in group to the
local administrator group on every PC using restricted groups GPO?


Basically I want an easy way to make sure all users are local admins on
their PCs without creating a custom group.  Should I just use xxx\domain
users instead?




List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/


List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to