how to assign specific user to the local admin group when computer join to the domain
  Home FAQ Contact Sign in
microsoft.public.windows.server.general only
 
Advanced search
POPULAR GROUPS

more...

microsoft ... server.general Profile…
 Up
how to assign specific user to the local admin group when computer join to the domain         


Author: OM
Date: Feb 11, 2008 14:29

Hi,

Windows by default assign the domain admins group to the local
administrator group when the PC firstly join to the domain. Can someone
advice me how do I do that for a specific user?

Thanks
7 Comments
Re: how to assign specific user to the local admin group when computer join to the domain         


Author: Marcin
Date: Feb 11, 2008 14:40

The simplest way to accomplish this would be to add that user to the Domain
Admins group...

hth
Marcin
no comments
Re: how to assign specific user to the local admin group when computer join to the domain         


Author: OM
Date: Feb 11, 2008 15:38

Thanks, But I don't the account to be part of the domain admin though

Marcin wrote:
> The simplest way to accomplish this would be to add that user to the
> Domain Admins group...
>
> hth
> Marcin
no comments
Re: how to assign specific user to the local admin group when comp         


Author: Anteaus
Date: Feb 12, 2008 01:20

"Marcin" wrote:
> The simplest way to accomplish this would be to add that user to the Domain
> Admins group...
>

NO!!!!!!!!
If you do that, the user can take control of the server over the LAN, and do
whatever mischief they like to it. And, then some.

The correct method for giving a user full local control is to use a
loginscript with a NET LOCALGROUP command,e.g.

net localgroup Administrators /add jsmith

Ths will give the user full control over the local computer, but without the
rights to remote-manage other computers.

Either that, or it can be achieved through group policy.
1 Comment
Re: how to assign specific user to the local admin group when computerjoin to the domain         


Date: Feb 12, 2008 01:26

Hello OM,

For this you can use the Restricted groups feature form Active Direrctory
in aGPO:
http://www.frickelsoft.net/blog/?p=13

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
> Hi,
>
> Windows by default assign the domain admins group to the local
> administrator group when the PC firstly join to the domain. Can
> someone advice me how do I do that for a specific user?
>
> Thanks
>
no comments
Re: how to assign specific user to the local admin group when comp         


Author: Saral6978
Date: Feb 12, 2008 06:03

Why can't you just right-click My Computer go to Manage-->Local Users and
Groups-->Groups and just add the domain account to the local administrators
group? That is how I always do it. Am I misunderstanding what is being
asked? After I join a PC to the domain, before I reboot the computer for
the changes to take effect, I follow my procedure above and it adds it no
problem (you do have to again supply an account with the proper credentials).
Then when I reboot the computer, the user's account is already added to
the local admins group and ready to go.
Show full article (1.20Kb)
no comments
Re: how to assign specific user to the local admin group when computerjoin to the domain         


Author: OM
Date: Feb 12, 2008 09:15

Thanks for all the input.

I guess what I want is this process is automatic and it is part of the
process when the machine is joined to the domain. We have couple more
admin. and sometimes one might forget to add the account to the local
admin group.

OM
Show full article (0.98Kb)
1 Comment
Re: how to assign specific user to the local admin group when computerjointo the domain         


Date: Feb 12, 2008 13:08

Hello OM,

Restricted groups is a one time only configuration. If you add a myadmingroup
(create in Active directory) and the local administrator, you have all you
need. In the myadmingroup you add all accounts you like to be local administrator.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
> Thanks for all the input.
>
> I guess what I want is this process is automatic and it is part of the
> process when the machine is joined to the domain. We have couple more
> admin. and sometimes one...
Show full article (1.50Kb)
no comments

RELATED THREADS
SubjectArticles qty Group
Entourage 2008 blocking web base domain and email for this domainmicrosoft.public.mac.office.entourage ·