You could probably use a combination of restricted groups and the 
userWorkstations attribute to accomplish this. All users are potential 
administrators on all computers, but users are locked down to specific 
computers that they can login to. Not that it would be inexpensive or magical, 
but it would be native.

Hunter

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]
Sent: Saturday, October 29, 2005 9:23 PM
To: [email protected]
Subject: RE: [ActiveDir] Restricted Groups question

The point is - he can't ensure that users are local admins on THEIR computers. 
Whether he uses interactive or domain users or everyone or just simply users, 
what he will get is "anyone who logs into this computer is an admin" which 
means he is making users local admins on ANY computer. The same result is 
achieved using option #2. In effect, anybody can be an admin on any computer.
 
In short, there is no inexpensive, magical, native way to do what he is 
expecting to do. It may be not very expensive in SBS land (I mean .....
c'mon, how tedious can adding users to groups on 75 computers - or however much 
they let you guys have these days - be <vbg>?). But in non-SBS space, well.... 
do the math.
 
So, again, the shortest (maybe most honest :)) answer (IMHO) to the question
is: You can't, at least not natively.
 
 
Sincerely,

Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I
Microsoft MVP - Directory Services
www.readymaids.com - we know IT
www.akomolafe.com
Do you now realize that Today is the Tomorrow you were worried about Yesterday? 
 -anon

________________________________

From: [EMAIL PROTECTED] on behalf of Susan Bradley
Sent: Sat 10/29/2005 7:39 PM
To: [email protected]
Subject: Re: [ActiveDir] Restricted Groups question



Now keep in mind that SBS's connection wizard does this for us and my manual 
memory 'how to' is a bit rusty....but I think the normal process includes 
creating an AD security group called "Workstation Admin", and add that group to 
the local admins group on each computer for existing machines.

 From the server... if you manage the computer & add it in the local users & 
groups . Then you can simply add users to the AD group as needed.

For existing deployed computers...this is our normal recommendation:


1)    On each PC, add the INTERACTIVE group to the Administrators group.
This will automatically give each user that logs in local Admin rights.
Downside is that if you ever want a user to not have local admin rights, you 
won't be able to restrict them as long as you have this configuration.


2)    Create a Security Group within AD (e.g. Local Admins).  On each
workstation, add the domain Local Admins group you created to the local 
Administrators group.  Then on your SBS, add your existing users to the Local 
Admins group, and create a new user template that includes Local Admins group 
membership.  When you create a new user, use the custom template and they'll be 
included in the Local Admins security group, which will give them local admin 
rights on the machines where you added the Local Admins group to the local 
Administrators group.


3)    Preferred solution:  Don't give users local admin rights.  Find your
problem apps that don't run as a restricted user and start nagging the vendor.  
Ask why they find exposing your business to undue risk as a justified business 
practice on their part.  Find what directories / reg keys those apps want 
access to and tweak the permissions accordingly to allow restricted users to be 
able to access those locations (and thus run the problem apps).




[EMAIL PROTECTED] wrote:

>I'm splitting hair here, but .......
>
>What you've recommended still doesn't achieve his stated goal - to make
users
>local admin rights on THEIR PCs.
>
>
>Sincerely,
>
>Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I
>Microsoft MVP - Directory Services
>www.readymaids.com - we know IT
>www.akomolafe.com
>Do you now realize that Today is the Tomorrow you were worried about 
>Yesterday?  -anon
>
>________________________________
>
>From: [EMAIL PROTECTED] on behalf of Susan Bradley, 
>CPA aka Ebitz - SBS Rocks [MVP]
>Sent: Sat 10/29/2005 8:00 AM
>To: [email protected]
>Subject: Re: [ActiveDir] Restricted Groups question
>
>
>
>What he's trying to do here [my read anyway] is automatically have 
>everyone as local admin on their PCs from the get go.  So that when 
>they log into the domain, they will be admins on their system.
>
>http://groups.google.com/group/microsoft.public.win2000.security/browse
>_frm/
t
>hread/9570ac134b07abff/60eb0461cf4af321?lnk=st&q=local+administrator+gr
>oup+p
o
>licy&rnum=8#60eb0461cf4af321
>
>The gurus recommend setting up a new OU and leave your existing ones as is.
>
>Now... that I've said you can, you do realize that your employees can 
>now do everything and ANYTHING on their systems.
>
>Have an acceptable use policy in place to define what they can and 
>cannot do.
>
>Be prepared to get malware and have to flatten a machine or two or three.
>
>Za Vue wrote:
>
> 
>
>>Just tell everyone to log in using the default Administrator account 
>>and leave the password blank. Tell the users to change it later.
>>What company is this?
>>
>>   
>>
>>>Is there any way to add "Authenticated Users" built-in group to the 
>>>local administrator group on every PC using restricted groups GPO?
>>>
>>>
>>>Basically I want an easy way to make sure all users are local admins 
>>>on their PCs without creating a custom group.  Should I just use 
>>>xxx\domain users instead?
>>>
>>>
>>>
>>>
>>>     
>>>
>>List info   : http://www.activedir.org/List.aspx
>>List FAQ    : http://www.activedir.org/ListFAQ.aspx
>>List archive: 
>>http://www.mail-archive.com/activedir%40mail.activedir.org/
>>
>>   
>>
>List info   : http://www.activedir.org/List.aspx
>List FAQ    : http://www.activedir.org/ListFAQ.aspx
>List archive: 
>http://www.mail-archive.com/activedir%40mail.activedir.org/
>
>
>List info   : http://www.activedir.org/List.aspx
>List FAQ    : http://www.activedir.org/ListFAQ.aspx
>List archive: 
>http://www.mail-archive.com/activedir%40mail.activedir.org/
>
> 
>
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/


List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to