PC Review


Reply
Thread Tools Rate Thread

Administering OUs

 
 
Srinivas Acharya
Guest
Posts: n/a
 
      20th Jul 2004
Hi All,
I have created OU in active directory and added many number
of computers to that OU. I want some body to manage that
OU. I mean that person should be able to carry out all the
admin tasks if he locally logs on to those computers,
coming under that OU only. He should not have admin
previliges on other computers of different OU.

One way to do this is by go on adding that user to local
admins group of all workstations. This is lenthy process. I
want to achieve this by simply defining administrator for
that OU?.

Is it possible to do that. If possible, how?. Can you
eloborate please?. Some body told in my earlier related
query that it is possible by restricted groups?. They have
not eloborated? I don't know what are these restricted
groups? what is the purpose of them?..

Thanks in advance.
Regards,
Srinivas Acharya
 
Reply With Quote
 
 
 
 
Tomasz Onyszko
Guest
Posts: n/a
 
      20th Jul 2004
Srinivas Acharya wrote:
> Is it possible to do that. If possible, how?. Can you
> eloborate please?. Some body told in my earlier related
> query that it is possible by restricted groups?. They have
> not eloborated? I don't know what are these restricted
> groups? what is the purpose of them?..


Yes, restricted groups are proper solution for this problem.
Restricted groups are defined in the GPO (for example GPO assigned on
the OU level) to force content of specified security group - for example
local administrators on client machine. IF You set this settings in
GPO on the OU level and then define in this GPO that in the builtin
administrators group only UsersA,UserB and DOmain Admins can be a member
of local administrators group this setting will be forced on all
machines affected by this GPO.
If somebody change this group membership on the next time policy will
applied the membership of local administrators group (for example) will
be set as defined in GPO.

--
Tomasz Onyszko [MVP]
(E-Mail Removed)
http://www.w2k.pl
 
Reply With Quote
 
Srinivas Acharya
Guest
Posts: n/a
 
      21st Jul 2004
Hi,
"
IF You set this settings in
>GPO on the OU level and then define in this GPO that in

the builtin administrators group only UsersA,UserB and
DOmain Admins can be a member of local administrators group
this setting will be forced on all machines affected by
this GPO".

This is fine. But I don't how to configure this.Please help me.

Regards,
Srinivas Acharya
>-----Original Message-----
>Srinivas Acharya wrote:
>> Is it possible to do that. If possible, how?. Can you
>> eloborate please?. Some body told in my earlier related
>> query that it is possible by restricted groups?. They have
>> not eloborated? I don't know what are these restricted
>> groups? what is the purpose of them?..

>
>Yes, restricted groups are proper solution for this problem.
>Restricted groups are defined in the GPO (for example GPO

assigned on
>the OU level) to force content of specified security group

- for example
> local administrators on client machine. IF You set this

settings in
>GPO on the OU level and then define in this GPO that in

the builtin
>administrators group only UsersA,UserB and DOmain Admins

can be a member
>of local administrators group this setting will be forced

on all
>machines affected by this GPO.
>If somebody change this group membership on the next time

policy will
>applied the membership of local administrators group (for

example) will
>be set as defined in GPO.
>
>--
>Tomasz Onyszko [MVP]
>(E-Mail Removed)
>http://www.w2k.pl
>.
>

 
Reply With Quote
 
Tomasz Onyszko
Guest
Posts: n/a
 
      21st Jul 2004
Srinivas Acharya wrote:

> This is fine. But I don't how to configure this.Please help me.

OK, create a GPO on the OU and edit it - next: Computer configuration ->
Windows Settings -> Security Settings -> Restricted groups

Rigth click -> add group -> Administrators



--
Tomasz Onyszko [MVP]
(E-Mail Removed)
http://www.w2k.pl
 
Reply With Quote
 
Srinivas Acharya
Guest
Posts: n/a
 
      21st Jul 2004
Hi
Thanks for the quick answer.

I know that.But I can't understand how it will work because
I added domain user to administrator group in the
restricted group of GPO on that OU. But when login as that
user on that PC, I don't have admin previleges. Is there
any thing that I have to do.
Regards,
Srinivas Acharya

>-----Original Message-----
>Srinivas Acharya wrote:
>
>> This is fine. But I don't how to configure this.Please

help me.
>OK, create a GPO on the OU and edit it - next: Computer

configuration ->
>Windows Settings -> Security Settings -> Restricted groups
>
>Rigth click -> add group -> Administrators
>
>
>
>--
>Tomasz Onyszko [MVP]
>(E-Mail Removed)
>http://www.w2k.pl
>.
>

 
Reply With Quote
 
Srinivas Acharya
Guest
Posts: n/a
 
      21st Jul 2004
Hi,
Any how I managed to add the domain user to local
administrator group with the help of restricted groups. but
now I have moved that PC from that OU. But still that user
is in the administrator group. Why still that user is
having admin previleges even though that user is no more in
that OU. Please any of you could address this issue?.
Regards,
Srinivas Acharya


>-----Original Message-----
>Hi
>Thanks for the quick answer.
>
>I know that.But I can't understand how it will work because
>I added domain user to administrator group in the
>restricted group of GPO on that OU. But when login as that
>user on that PC, I don't have admin previleges. Is there
>any thing that I have to do.
>Regards,
>Srinivas Acharya
>
>>-----Original Message-----
>>Srinivas Acharya wrote:
>>
>>> This is fine. But I don't how to configure this.Please

>help me.
>>OK, create a GPO on the OU and edit it - next: Computer

>configuration ->
>>Windows Settings -> Security Settings -> Restricted groups
>>
>>Rigth click -> add group -> Administrators
>>
>>
>>
>>--
>>Tomasz Onyszko [MVP]
>>(E-Mail Removed)
>>http://www.w2k.pl
>>.
>>

>.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Administering XP Pro Pat Windows XP General 9 14th Oct 2007 05:05 PM
Administering IIS on XP =?Utf-8?B?U2ltb24=?= Windows XP Security 4 9th Mar 2005 10:25 AM
Administering RRAS with XP Mike Bright MSP Windows XP Security 2 28th Jul 2004 06:26 PM
Administering another domain? Jackal Microsoft Windows 2000 Active Directory 2 10th Jun 2004 04:50 PM
Administering without Administrator dp Microsoft Windows 2000 Setup 1 13th Feb 2004 08:38 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:17 AM.