I'm not sure I follow. Do you mean you have a separate local or domain group
for administration of the local workstation? For our staff, I wanted to
permit them to install software, manage their printers, and such like
without our intervention (some use little label printers, Palm devices, and
the like). So if each user is an administrator (along with the Domain
Admins) of his individual workstation, that's OK. So we added just the
individual domain user (the account they regularly logged in as) into the
local Administrators group, they have admin rights for that workstation
only. Using a group, each staffer would have administrative rights for every
other workstation, too. We didn't want to do that. Since it's a global
account in a local group, it has to be done on each workstation, but only
once. I did err in the beginning by putting the local user
(\WORKSTATION\Username) in the Administrators group instead of the domain
account (\DOMAIN\Username). Since they have to login to the domain to get to
the server shares, the local user account isn't actually used (and doesn't
exist on many machines, but did on some--hence my confusion). This is a very
messy topic. Best explication I've seen yet is in Minasi, Anderson, and
Creegan, Mastering Windows NT Server 4 (Sybex). That one's on the nearest
shelf over my desk.
--Cal Frye, Western Reserve Academy, Hudson, Ohio
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Robert Everland
III
Sent: Friday, November 05, 1999 3:19 PM
To: [EMAIL PROTECTED]
Subject: Re: [IMail Forum] Off topic - User Rights
Carl one thing I did notice though is that if the users are the same name as
the
domain it still doesn't work. The only way to get it so they have rights on
the
computer is to make a group with all the users in it and use the group. The
users that I wanted access to on the computer were already there but when I
added a new group I made I was able to be the admin on that computer but
still
have the rights on the shares I needed.
Bob Everland
Cal Frye wrote:
> Robert--
> I don't see this elsewhere on the list (haven't gotten through today's
inbox
> yet), so I'll have a go.
> We're doing this around here with our administrative machines, and I'm
sorry
> we didn't do it when we installed 'em. Go to each workstation (ugh!) and
> login as administrator. Open the User Manager (NOT the user manager for
> domains). Open the Administrator's group (the local one). Click the Add
> button, and be sure to select the desired local user FROM THE DOMAIN users
> list (see the List Names From dropdown box). Took me a while to catch on
to
> the fact that the domain user isn't the same as the local user of the same
> name. Now it works.
>
> --Cal Frye, Western Reserve Academy, Hudson, Ohio
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Robert Everland
> III
> Sent: Thursday, November 04, 1999 6:33 PM
> To: [EMAIL PROTECTED]
> Subject: [IMail Forum] Off topic - User Rights
>
> I am running a mix enviroment of NT Server and NT Workstation. When the
NT
> workstations log on to the NT server I can't do anything locally to the
> machine, as
> in share files, use the user mahcine and get any share that I process
though
> loing
> scripts unless they are a member of Domain Admins which is a global group.
> Only
> thing though that is if they are a member of Domain Admin they are able to
> do
> everything to the computer and I have no idea why. Where are the rights
for
> groups
> given at? I would like the computers to have admin rights at thier
computers
> only
> and have the rights I give them at the shares seperate. Can I even do this
> for NT
> workstation or do I have to log on locally and do it like that? I used to
> have a
> domain with all 95 98 and since there are no computer rights they were
able
> to do
> whatever they wanted. Also no policies are enable disabling anything.
>
> Bob Everland
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.