The point is - he can't ensure that users are local admins on THEIR computers. Whether he uses interactive or domain users or everyone or just simply users, what he will get is "anyone who logs into this computer is an admin" which means he is making users local admins on ANY computer. The same result is achieved using option #2. In effect, anybody can be an admin on any computer. In short, there is no inexpensive, magical, native way to do what he is expecting to do. It may be not very expensive in SBS land (I mean ..... c'mon, how tedious can adding users to groups on 75 computers - or however much they let you guys have these days - be <vbg>?). But in non-SBS space, well.... do the math. So, again, the shortest (maybe most honest :)) answer (IMHO) to the question is: You can't, at least not natively. Sincerely,
Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon ________________________________ From: [EMAIL PROTECTED] on behalf of Susan Bradley Sent: Sat 10/29/2005 7:39 PM To: [email protected] Subject: Re: [ActiveDir] Restricted Groups question Now keep in mind that SBS's connection wizard does this for us and my manual memory 'how to' is a bit rusty....but I think the normal process includes creating an AD security group called "Workstation Admin", and add that group to the local admins group on each computer for existing machines. From the server... if you manage the computer & add it in the local users & groups . Then you can simply add users to the AD group as needed. For existing deployed computers...this is our normal recommendation: 1) On each PC, add the INTERACTIVE group to the Administrators group. This will automatically give each user that logs in local Admin rights. Downside is that if you ever want a user to not have local admin rights, you won't be able to restrict them as long as you have this configuration. 2) Create a Security Group within AD (e.g. Local Admins). On each workstation, add the domain Local Admins group you created to the local Administrators group. Then on your SBS, add your existing users to the Local Admins group, and create a new user template that includes Local Admins group membership. When you create a new user, use the custom template and they'll be included in the Local Admins security group, which will give them local admin rights on the machines where you added the Local Admins group to the local Administrators group. 3) Preferred solution: Don't give users local admin rights. Find your problem apps that don't run as a restricted user and start nagging the vendor. Ask why they find exposing your business to undue risk as a justified business practice on their part. Find what directories / reg keys those apps want access to and tweak the permissions accordingly to allow restricted users to be able to access those locations (and thus run the problem apps). [EMAIL PROTECTED] wrote: >I'm splitting hair here, but ....... > >What you've recommended still doesn't achieve his stated goal - to make users >local admin rights on THEIR PCs. > > >Sincerely, > >Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I >Microsoft MVP - Directory Services >www.readymaids.com - we know IT >www.akomolafe.com >Do you now realize that Today is the Tomorrow you were worried about >Yesterday? -anon > >________________________________ > >From: [EMAIL PROTECTED] on behalf of Susan Bradley, CPA aka >Ebitz - SBS Rocks [MVP] >Sent: Sat 10/29/2005 8:00 AM >To: [email protected] >Subject: Re: [ActiveDir] Restricted Groups question > > > >What he's trying to do here [my read anyway] is automatically have >everyone as local admin on their PCs from the get go. So that when they >log into the domain, they will be admins on their system. > >http://groups.google.com/group/microsoft.public.win2000.security/browse_frm/ t >hread/9570ac134b07abff/60eb0461cf4af321?lnk=st&q=local+administrator+group+p o >licy&rnum=8#60eb0461cf4af321 > >The gurus recommend setting up a new OU and leave your existing ones as is. > >Now... that I've said you can, you do realize that your employees can >now do everything and ANYTHING on their systems. > >Have an acceptable use policy in place to define what they can and >cannot do. > >Be prepared to get malware and have to flatten a machine or two or three. > >Za Vue wrote: > > > >>Just tell everyone to log in using the default Administrator account >>and leave the password blank. Tell the users to change it later. >>What company is this? >> >> >> >>>Is there any way to add "Authenticated Users" built-in group to the >>>local administrator group on every PC using restricted groups GPO? >>> >>> >>>Basically I want an easy way to make sure all users are local admins on >>>their PCs without creating a custom group. Should I just use xxx\domain >>>users instead? >>> >>> >>> >>> >>> >>> >>List info : http://www.activedir.org/List.aspx >>List FAQ : http://www.activedir.org/ListFAQ.aspx >>List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ >> >> >> >List info : http://www.activedir.org/List.aspx >List FAQ : http://www.activedir.org/ListFAQ.aspx >List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ > > >List info : http://www.activedir.org/List.aspx >List FAQ : http://www.activedir.org/ListFAQ.aspx >List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ > > > List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
