Delegate Control

G

Guest

I need to delegate control of some computers to a user. I have 1 O.U. with the computers but i don't understand how to delegate some powers like add and remove programs. I need to give to this user the administration of some computers
Thanks.
 
G

Guest

Hi

if I understand you correctly, you want to make a group of users administrators for some client machines. If this is correct, it has nothing to do with "delegation of control" in Active Directory, as you do not want to delegate some administrative rights over Active Directory objects
When you want to make some users or a certain group administrators of client machines, you should evaluate using the "Restricted groups" setting in Group Policy. By using "Restricted groups", you can configure who should be a member of a certain group - by this, you could make a certain Domain group to always be a member of the local "Administrators" group of the client workstations. Make sure that you include ALL groups that should belong to the local Administrators group in the "Restricted Groups" policy as this is a "replace" rather than a "merge" policy
For such a topic, I recommend that you use a computer startup script in Group Policy to check if the Domain group is a member of the local Administrators group. If not, the script can add the group.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top