![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
Local Admin on all machines and add comp to domainthis thread has 11 replies and has been viewed 3115 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||||||
|
||||||||
|
Hello all,
I have been doing some research on how to do these two things, but I don't seem to be having much luck on these specific issues. I currently have domain admins, which of course has all of the system administrators. I recently created a group called Desktop Support, which will house the...can we guess...desktop support people. I need this desktop support group to have two things:
As for my computer name structure, they are in different OUs. So when I add a machine to the domain, it ends up in the Computers folder. After that, I move the computer into a different OU called either Laptop, Desktops or Servers. Thank you for taking a look and reading. If you have any suggestions, I thank you in advance. |
|
#2
|
||||||||
|
||||||||
|
I am sorry, I guess I missed the GPO forum. I will post this there.
Once again, sorry. |
|
#3
|
||||||||
|
||||||||
|
Hello all,
I have been doing some research on how to do these two things, but I don't seem to be having much luck on these specific issues. I currently have domain admins, which of course has all of the system administrators. I recently created a group called Desktop Support, which will house the...can we guess...desktop support people. I need this desktop support group to have two things: The ability to add computers to the domain. Setup the group as a local administrator on all client PCs (not servers). As for my computer name structure, they are in different OUs. So when I add a machine to the domain, it ends up in the Computers folder. After that, I move the computer into a different OU called either Laptop, Desktops or Servers. Thank you for taking a look and reading. If you have any suggestions, I thank you in advance. |
|
#4
|
||||||||||
|
||||||||||
|
A Mod can move the post instead of you double posting..
To answer your question, take a look at Restricted Groups in the GPO. Add the group in the local administrators that way. Then, you might want to delegate control over the computer objects in the OU where desktops are to the same group, as I suppose they will be joining machines to the domain etc.. |
|
#5
|
|||||||||
|
|||||||||
|
We have two groups:
Desktop Support: gGpl_AddGrouptoLocalAdminsGroup Domain Admins: Domain Admins We add both groups to all Local Administrators groups on workstations by GPO: Computer Configuration\Windows Settings\Security Settings\Restricted Groups GroupName = Administrators Members = myDomain\gGpl_AddGrouptoLocalAdminsGroup, myDomain\Domain Admins Of course you apply this GPO to the OU with your workstations as your servers will be in their own, seperate OU. Your Desktop users should be in the "gGpl_AddGrouptoLocalAdminsGroup" group. As for adding computers to the domain, edit "Default Domain Controller" group policy under "Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment\". Here look for policy named "Add workstations to domain" and double click on it. Now add the group "gGpl_AddGrouptoLocalAdminsGroup" to this policy. Wait for the replication to finish between the DCs and your help desk personnel is now able to add workstations to domain.
__________________
| +-- JDMils | +-- System Admin, DotNet programmer & Jack of all trades | |
|
#6
|
||||||||
|
||||||||
|
I appreciate you getting back to me on this. I have been doing research and stumbled across the restricted groups policy. I had a question about the way it works though. If I setup restricted groups, can I still add individual users to the local admin group? Many of my users need to be local admins on their machines because of the type of work and software they do/use. This is something I will need to test.
As for the adding machines to the domain, I did edit that GPO but it doesn't seem to help with anything. My support group is still having problems adding machines to the domain. Anyone have any ideas about what could be causing this? |
|
#7
|
||||||||
|
||||||||
|
Quote:
It it possible to have the mods delete this post or lock it or something.... |
|
#8
|
||||||||||
|
||||||||||
|
Moved to GPO forum at OPs request
And merged with the other thread Reasons not to double post number 403.5......
__________________
Tom Jones MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+ PhD, MSc, FIAP, MIITT IT Trainer / Consultant Ossian Ltd Scotland ** Remember to give credit where credit is due and leave reputation points where appropriate ** Last edited by Ossian; 16th May 2008 at 12:50.. |
|
#9
|
||||||||
|
||||||||
|
Quote:
This works great, but the only problem I have is that if I do this to all of my computers in the domain, it overwrites what is currently in the local administrators group. The majority of my users need to be a local admin on their box. Is there a way around this...or maybe a GPO that allows you to create local groups on the machine itself. Thank you once again. |
|
#10
|
||||||||
|
||||||||
|
I figured out what I did wrong with the restricted groups. I setup the reverse...I had it overwrite instead of add my domain group to the local group. Sorry...my brain is fried.
Now I just need to figure out why I can't setup my desktop support group to add machines to the domain. I added them to the GPO and delegated control to them, but it still doesn't seem to be working. I am getting an access is denied error. |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| change admin password for local comp using batch | hshaik | General Scripting | 3 | 9th April 2007 23:52 |
| Add Domain user/group as winXP local Administrator | ebe75 | GPO | 13 | 25th March 2007 01:04 |
| Win2003 Domain Controller lost Local Admin & Domain Admin pwds | OdinTrisk | Forgot Administrator Password | 2 | 7th January 2007 22:44 |
| New Domain, Need All users to have Local Admin | spepi | GPO | 6 | 27th December 2006 17:15 |
| add comp and user account for a new comp by a script | avivh | General Scripting | 1 | 25th December 2004 22:33 |