|
#1
|
|||
|
|||
|
Hello everybody
My users domain accounts are in the local administrators groups of their local XP PC's. I want to move the domain accounts from local administrators to a group where they can still install ALL software, change the system time, install windows updates, and all other user tasks BUT that they do not have the right to change the domain membership, create new local users, add (or remove) users to the local admins user group. Power users cannot install all software (rising to most software for some users) so that isn't a solution. Really, it's not. I believe I need to create a new custom local group on each PC, add the users domain accounts to it and somehow grant that account enough rights to do the above tasks, whilst dening them the rights to change domain membership, etc. N.B. We (will soon!) have a 2003 domain for group policies, etc. How do I go about assigning these rights to a custom local group? How do I automate this for 250 XP PC's? Thanks in advance Andy. |
|
#2
|
|||
|
|||
|
What you want to do is not possible. They will need to be local
administrators from your description. Having said that you can use Group Policy to restrict enough access to even the local administrator to deter all but the most skilled and determined users. For instance you can block access to mmc snapins, the registry, the command prompt, etc and use Software Restriction Policies to restrict what a user can install and run on there computer though a local administrator can bypass SRP by booting into safe mode if they know such. Also any .msi software packages can be assigned or published via Group Policy so that they can be installed by the "computer" or user even if they do not have any elevated privileges normally. --- Steve <andy_cafferkey@hotmail.com> wrote in message news:%23$Yoh3X1FHA.3300@TK2MSFTNGP15.phx.gbl... > Hello everybody > > My users domain accounts are in the local administrators groups of their > local XP PC's. > I want to move the domain accounts from local administrators to a group > where they can still install ALL software, change the system time, install > windows updates, and all other user tasks > BUT > that they do not have the right to change the domain membership, create > new local users, add (or remove) users to the local admins user group. > > Power users cannot install all software (rising to most software for some > users) so that isn't a solution. Really, it's not. > > I believe I need to create a new custom local group on each PC, add the > users domain accounts to it and somehow grant that account enough rights > to do the above tasks, whilst dening them the rights to change domain > membership, etc. > > N.B. We (will soon!) have a 2003 domain for group policies, etc. > > How do I go about assigning these rights to a custom local group? > How do I automate this for 250 XP PC's? > > Thanks in advance > > Andy. > > |
|
#3
|
|||
|
|||
|
Thanks for your reply.
Andy "Steven L Umbach" <n9rou@n0-spam-for-me-comcast.net> wrote in message news:GZCdnWIzNZS8-MfeRVn-rA@comcast.com... > What you want to do is not possible. They will need to be local > administrators from your description. Having said that you can use Group > Policy to restrict enough access to even the local administrator to deter > all but the most skilled and determined users. For instance you can block > access to mmc snapins, the registry, the command prompt, etc and use > Software Restriction Policies to restrict what a user can install and run > on there computer though a local administrator can bypass SRP by booting > into safe mode if they know such. Also any .msi software packages can be > assigned or published via Group Policy so that they can be installed by > the "computer" or user even if they do not have any elevated privileges > normally. --- Steve > > > <andy_cafferkey@hotmail.com> wrote in message > news:%23$Yoh3X1FHA.3300@TK2MSFTNGP15.phx.gbl... >> Hello everybody >> >> My users domain accounts are in the local administrators groups of their >> local XP PC's. >> I want to move the domain accounts from local administrators to a group >> where they can still install ALL software, change the system time, >> install windows updates, and all other user tasks >> BUT >> that they do not have the right to change the domain membership, create >> new local users, add (or remove) users to the local admins user group. >> >> Power users cannot install all software (rising to most software for some >> users) so that isn't a solution. Really, it's not. >> >> I believe I need to create a new custom local group on each PC, add the >> users domain accounts to it and somehow grant that account enough rights >> to do the above tasks, whilst dening them the rights to change domain >> membership, etc. >> >> N.B. We (will soon!) have a 2003 domain for group policies, etc. >> >> How do I go about assigning these rights to a custom local group? >> How do I automate this for 250 XP PC's? >> >> Thanks in advance >> >> Andy. >> >> > > |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Downloading all updates after SP2 | Kevin Benstead | Windows Update | 6 | 01-05-2006 05:15 PM |
| Windows XP View | YoGro International | Windows XP Customize | 2 | 01-05-2006 06:33 AM |
| My words | Panda_man | Windows XP New Users | 4 | 01-05-2006 02:53 AM |
| Delay opening folders caused by dcom server process launcher service | None | Windows XP Help and Support | 5 | 01-05-2006 02:46 AM |
| reinstalling windows xp | Janice | Windows XP Help and Support | 3 | 01-05-2006 02:43 AM |