The point is - he can't ensure that users are local admins on THEIR
computers. Whether he uses interactive or domain users or everyone or just
simply users, what he will get is "anyone who logs into this computer is an
admin" which means he is making users local admins on ANY computer. The same
result is achieved using option #2. In effect, anybody can be an admin on any
computer.
 
In short, there is no inexpensive, magical, native way to do what he is
expecting to do. It may be not very expensive in SBS land (I mean .....
c'mon, how tedious can adding users to groups on 75 computers - or however
much they let you guys have these days - be <vbg>?). But in non-SBS space,
well.... do the math.
 
So, again, the shortest (maybe most honest :)) answer (IMHO) to the question
is: You can't, at least not natively.
 
 
Sincerely,

Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I
Microsoft MVP - Directory Services
www.readymaids.com - we know IT
www.akomolafe.com
Do you now realize that Today is the Tomorrow you were worried about
Yesterday?  -anon

________________________________

From: [EMAIL PROTECTED] on behalf of Susan Bradley
Sent: Sat 10/29/2005 7:39 PM
To: [email protected]
Subject: Re: [ActiveDir] Restricted Groups question



Now keep in mind that SBS's connection wizard does this for us and my
manual memory 'how to' is a bit rusty....but I think the normal process
includes creating an AD security group called "Workstation Admin", and
add that group to the local admins group on each computer for existing
machines.

 From the server... if you manage the computer & add it in the local
users & groups . Then you can simply add users to the AD group as needed.

For existing deployed computers...this is our normal recommendation:


1)    On each PC, add the INTERACTIVE group to the Administrators group.
This will automatically give each user that logs in local Admin rights.
Downside is that if you ever want a user to not have local admin rights,
you
won't be able to restrict them as long as you have this configuration.


2)    Create a Security Group within AD (e.g. Local Admins).  On each
workstation, add the domain Local Admins group you created to the local
Administrators group.  Then on your SBS, add your existing users to the
Local Admins group, and create a new user template that includes Local
Admins group membership.  When you create a new user, use the custom
template and they'll be included in the Local Admins security group, which
will give them local admin rights on the machines where you added the Local
Admins group to the local Administrators group.


3)    Preferred solution:  Don't give users local admin rights.  Find your
problem apps that don't run as a restricted user and start nagging the
vendor.  Ask why they find exposing your business to undue risk as a
justified business practice on their part.  Find what directories / reg
keys
those apps want access to and tweak the permissions accordingly to allow
restricted users to be able to access those locations (and thus run the
problem apps).




[EMAIL PROTECTED] wrote:

>I'm splitting hair here, but .......
>
>What you've recommended still doesn't achieve his stated goal - to make
users
>local admin rights on THEIR PCs.
>
>
>Sincerely,
>
>Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I
>Microsoft MVP - Directory Services
>www.readymaids.com - we know IT
>www.akomolafe.com
>Do you now realize that Today is the Tomorrow you were worried about
>Yesterday?  -anon
>
>________________________________
>
>From: [EMAIL PROTECTED] on behalf of Susan Bradley, CPA aka
>Ebitz - SBS Rocks [MVP]
>Sent: Sat 10/29/2005 8:00 AM
>To: [email protected]
>Subject: Re: [ActiveDir] Restricted Groups question
>
>
>
>What he's trying to do here [my read anyway] is automatically have
>everyone as local admin on their PCs from the get go.  So that when they
>log into the domain, they will be admins on their system.
>
>http://groups.google.com/group/microsoft.public.win2000.security/browse_frm/
t
>hread/9570ac134b07abff/60eb0461cf4af321?lnk=st&q=local+administrator+group+p
o
>licy&rnum=8#60eb0461cf4af321
>
>The gurus recommend setting up a new OU and leave your existing ones as is.
>
>Now... that I've said you can, you do realize that your employees can
>now do everything and ANYTHING on their systems.
>
>Have an acceptable use policy in place to define what they can and
>cannot do.
>
>Be prepared to get malware and have to flatten a machine or two or three.
>
>Za Vue wrote:
>
> 
>
>>Just tell everyone to log in using the default Administrator account
>>and leave the password blank. Tell the users to change it later.
>>What company is this?
>>
>>   
>>
>>>Is there any way to add "Authenticated Users" built-in group to the
>>>local administrator group on every PC using restricted groups GPO?
>>>
>>>
>>>Basically I want an easy way to make sure all users are local admins on
>>>their PCs without creating a custom group.  Should I just use xxx\domain
>>>users instead?
>>>
>>>
>>>
>>>
>>>     
>>>
>>List info   : http://www.activedir.org/List.aspx
>>List FAQ    : http://www.activedir.org/ListFAQ.aspx
>>List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
>>
>>   
>>
>List info   : http://www.activedir.org/List.aspx
>List FAQ    : http://www.activedir.org/ListFAQ.aspx
>List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
>
>
>List info   : http://www.activedir.org/List.aspx
>List FAQ    : http://www.activedir.org/ListFAQ.aspx
>List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
>
> 
>
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/


List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to