Jump to content

Recommended Posts

Posted

The time has come where I've finally take on an apprentice technician to help me with managing the school!

I'm creating him a separate account from his standard login, with no profile attached etc. and that will be his administrator account for when he goes out to jobs.

 

Obviously I don't want him to have full unrestricted admin access, just install permissions and the basics to bypass UAC prompts.

 

What group could I add him into in AD to give just these permissions?

 

A quick Google was talking about the NT AUTHORITY groups, but I'm not overly familiar with these?

 

Thanks!

Posted

So will he require any access to servers if so what?

 

As for local admin on PC's you will need to either add his account or create a local admin's account and assign that via GPO security policy.

 

If it's just password resets at server level delegate access and install AD tools on his PC.

  • Thanks 1
Posted

I may give him access to a few servers a bit later on, like the print server etc. but not yet.

 

Is there a way to create a security group and deploy that? In the sense of 'if more technicians were appointed I could add them all to one group/or remove them. That way I don't have to do it for individual users'?

Posted

Create a security group in AD called say local administrators and modify your local security policy for the computers and add that in as a group so they only get local admin rights on the PC.

 

As for say print server you can manually add the group in the same way but just giving rights as a remote desktop user and print operators and away you go on say a print server.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...