Oh, you mean only let that person be admin on 'that' particular machine
and no other? Oh sorry I wasn't getting the limitation he was wanting here.
Well IMHO, if you are already thinking that 'hey we want to limit access
to just that machine' and thus already thinking of the consequences of
security you might as well bite the bullet, and pull out the
regmon/filemon and start yelling at your vendors.
[EMAIL PROTECTED] wrote:
The point is - he can't ensure that users are local admins on THEIR
computers. Whether he uses interactive or domain users or everyone or just
simply users, what he will get is "anyone who logs into this computer is an
admin" which means he is making users local admins on ANY computer. The same
result is achieved using option #2. In effect, anybody can be an admin on any
computer.
In short, there is no inexpensive, magical, native way to do what he is
expecting to do. It may be not very expensive in SBS land (I mean .....
c'mon, how tedious can adding users to groups on 75 computers - or however
much they let you guys have these days - be <vbg>?). But in non-SBS space,
well.... do the math.
So, again, the shortest (maybe most honest :)) answer (IMHO) to the question
is: You can't, at least not natively.
Sincerely,
Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I
Microsoft MVP - Directory Services
www.readymaids.com - we know IT
www.akomolafe.com
Do you now realize that Today is the Tomorrow you were worried about
Yesterday? -anon
________________________________
From: [EMAIL PROTECTED] on behalf of Susan Bradley
Sent: Sat 10/29/2005 7:39 PM
To: [email protected]
Subject: Re: [ActiveDir] Restricted Groups question
Now keep in mind that SBS's connection wizard does this for us and my
manual memory 'how to' is a bit rusty....but I think the normal process
includes creating an AD security group called "Workstation Admin", and
add that group to the local admins group on each computer for existing
machines.
From the server... if you manage the computer & add it in the local
users & groups . Then you can simply add users to the AD group as needed.
For existing deployed computers...this is our normal recommendation:
1) On each PC, add the INTERACTIVE group to the Administrators group.
This will automatically give each user that logs in local Admin rights.
Downside is that if you ever want a user to not have local admin rights,
you
won't be able to restrict them as long as you have this configuration.
2) Create a Security Group within AD (e.g. Local Admins). On each
workstation, add the domain Local Admins group you created to the local
Administrators group. Then on your SBS, add your existing users to the
Local Admins group, and create a new user template that includes Local
Admins group membership. When you create a new user, use the custom
template and they'll be included in the Local Admins security group, which
will give them local admin rights on the machines where you added the Local
Admins group to the local Administrators group.
3) Preferred solution: Don't give users local admin rights. Find your
problem apps that don't run as a restricted user and start nagging the
vendor. Ask why they find exposing your business to undue risk as a
justified business practice on their part. Find what directories / reg
keys
those apps want access to and tweak the permissions accordingly to allow
restricted users to be able to access those locations (and thus run the
problem apps).
[EMAIL PROTECTED] wrote:
I'm splitting hair here, but .......
What you've recommended still doesn't achieve his stated goal - to make
users
local admin rights on THEIR PCs.
Sincerely,
Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I
Microsoft MVP - Directory Services
www.readymaids.com - we know IT
www.akomolafe.com
Do you now realize that Today is the Tomorrow you were worried about
Yesterday? -anon
________________________________
From: [EMAIL PROTECTED] on behalf of Susan Bradley, CPA aka
Ebitz - SBS Rocks [MVP]
Sent: Sat 10/29/2005 8:00 AM
To: [email protected]
Subject: Re: [ActiveDir] Restricted Groups question
What he's trying to do here [my read anyway] is automatically have
everyone as local admin on their PCs from the get go. So that when they
log into the domain, they will be admins on their system.
http://groups.google.com/group/microsoft.public.win2000.security/browse_frm/
t
hread/9570ac134b07abff/60eb0461cf4af321?lnk=st&q=local+administrator+group+p
o
licy&rnum=8#60eb0461cf4af321
The gurus recommend setting up a new OU and leave your existing ones as is.
Now... that I've said you can, you do realize that your employees can
now do everything and ANYTHING on their systems.
Have an acceptable use policy in place to define what they can and
cannot do.
Be prepared to get malware and have to flatten a machine or two or three.
Za Vue wrote:
Just tell everyone to log in using the default Administrator account
and leave the password blank. Tell the users to change it later.
What company is this?
Is there any way to add "Authenticated Users" built-in group to the
local administrator group on every PC using restricted groups GPO?
Basically I want an easy way to make sure all users are local admins on
their PCs without creating a custom group. Should I just use xxx\domain
users instead?
List info : http://www.activedir.org/List.aspx
List FAQ : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info : http://www.activedir.org/List.aspx
List FAQ : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info : http://www.activedir.org/List.aspx
List FAQ : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info : http://www.activedir.org/List.aspx
List FAQ : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info : http://www.activedir.org/List.aspx
List FAQ : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info : http://www.activedir.org/List.aspx
List FAQ : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/