all domain user should have admin rights on single computer

A

Adnan

Hi,

I am running a domain on windows server 2003 with almost 200
computers.

I want that all the domains user should have the admin rights on a
particular computer that any time when a user connects to that
computer using the domain he can hve the complete admin rights. that
computer is also part of the domain.


can any body help me
 
M

Meinolf Weber

Hello Adnan,

Create a new OU move the compouter to it, create a new GPO and use Restricted
Groups from Computer configuration>Windows settings>Restricted Groups Here
you can configure the settings for your needs. If you are ready with it,
rightclick the policy name and check the securoty tab that apply Group policy
is checked. And do a test with one testuser account BEFORE and do not move
other computers to this OU, so that no other machines get the policy.

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
 
P

Paul Bergson [MVP-DS]

Just remember if a user has local admin rights, they can do anything. This
includes Trojan horses, games, spyware, etc... Think twice before you
blanketly give all your users free run of the environment.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top