Custom user group in windows XP


Go Back   Computer Help Articles > Windows XP Security Admin
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 04:16 AM
 
Posts: n/a
Default Custom user group in windows XP

Hello everybody

My users domain accounts are in the local administrators groups of their
local XP PC's.
I want to move the domain accounts from local administrators to a group
where they can still install ALL software, change the system time, install
windows updates, and all other user tasks
BUT
that they do not have the right to change the domain membership, create new
local users, add (or remove) users to the local admins user group.

Power users cannot install all software (rising to most software for some
users) so that isn't a solution. Really, it's not.

I believe I need to create a new custom local group on each PC, add the
users domain accounts to it and somehow grant that account enough rights to
do the above tasks, whilst dening them the rights to change domain
membership, etc.

N.B. We (will soon!) have a 2003 domain for group policies, etc.

How do I go about assigning these rights to a custom local group?
How do I automate this for 250 XP PC's?

Thanks in advance

Andy.


Reply With Quote
  #2  
Old 01-05-2006, 04:16 AM
Steven L Umbach
 
Posts: n/a
Default Re: Custom user group in windows XP

What you want to do is not possible. They will need to be local
administrators from your description. Having said that you can use Group
Policy to restrict enough access to even the local administrator to deter
all but the most skilled and determined users. For instance you can block
access to mmc snapins, the registry, the command prompt, etc and use
Software Restriction Policies to restrict what a user can install and run on
there computer though a local administrator can bypass SRP by booting into
safe mode if they know such. Also any .msi software packages can be assigned
or published via Group Policy so that they can be installed by the
"computer" or user even if they do not have any elevated privileges
normally. --- Steve


<andy_cafferkey@hotmail.com> wrote in message
news:%23$Yoh3X1FHA.3300@TK2MSFTNGP15.phx.gbl...
> Hello everybody
>
> My users domain accounts are in the local administrators groups of their
> local XP PC's.
> I want to move the domain accounts from local administrators to a group
> where they can still install ALL software, change the system time, install
> windows updates, and all other user tasks
> BUT
> that they do not have the right to change the domain membership, create
> new local users, add (or remove) users to the local admins user group.
>
> Power users cannot install all software (rising to most software for some
> users) so that isn't a solution. Really, it's not.
>
> I believe I need to create a new custom local group on each PC, add the
> users domain accounts to it and somehow grant that account enough rights
> to do the above tasks, whilst dening them the rights to change domain
> membership, etc.
>
> N.B. We (will soon!) have a 2003 domain for group policies, etc.
>
> How do I go about assigning these rights to a custom local group?
> How do I automate this for 250 XP PC's?
>
> Thanks in advance
>
> Andy.
>
>



Reply With Quote
  #3  
Old 01-05-2006, 04:17 AM
 
Posts: n/a
Default Re: Custom user group in windows XP

Thanks for your reply.

Andy

"Steven L Umbach" <n9rou@n0-spam-for-me-comcast.net> wrote in message
news:GZCdnWIzNZS8-MfeRVn-rA@comcast.com...
> What you want to do is not possible. They will need to be local
> administrators from your description. Having said that you can use Group
> Policy to restrict enough access to even the local administrator to deter
> all but the most skilled and determined users. For instance you can block
> access to mmc snapins, the registry, the command prompt, etc and use
> Software Restriction Policies to restrict what a user can install and run
> on there computer though a local administrator can bypass SRP by booting
> into safe mode if they know such. Also any .msi software packages can be
> assigned or published via Group Policy so that they can be installed by
> the "computer" or user even if they do not have any elevated privileges
> normally. --- Steve
>
>
> <andy_cafferkey@hotmail.com> wrote in message
> news:%23$Yoh3X1FHA.3300@TK2MSFTNGP15.phx.gbl...
>> Hello everybody
>>
>> My users domain accounts are in the local administrators groups of their
>> local XP PC's.
>> I want to move the domain accounts from local administrators to a group
>> where they can still install ALL software, change the system time,
>> install windows updates, and all other user tasks
>> BUT
>> that they do not have the right to change the domain membership, create
>> new local users, add (or remove) users to the local admins user group.
>>
>> Power users cannot install all software (rising to most software for some
>> users) so that isn't a solution. Really, it's not.
>>
>> I believe I need to create a new custom local group on each PC, add the
>> users domain accounts to it and somehow grant that account enough rights
>> to do the above tasks, whilst dening them the rights to change domain
>> membership, etc.
>>
>> N.B. We (will soon!) have a 2003 domain for group policies, etc.
>>
>> How do I go about assigning these rights to a custom local group?
>> How do I automate this for 250 XP PC's?
>>
>> Thanks in advance
>>
>> Andy.
>>
>>

>
>



Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Downloading all updates after SP2 Kevin Benstead Windows Update 6 01-05-2006 05:15 PM
Windows XP View YoGro International Windows XP Customize 2 01-05-2006 06:33 AM
My words Panda_man Windows XP New Users 4 01-05-2006 02:53 AM
Delay opening folders caused by dcom server process launcher service None Windows XP Help and Support 5 01-05-2006 02:46 AM
reinstalling windows xp Janice Windows XP Help and Support 3 01-05-2006 02:43 AM


All times are GMT. The time now is 04:53 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

Custom user group in windows XP