Jump to content

Recommended Posts

Posted

Is it possible to give a power user (with domain account) administrator privileges on a particular machine?

 

I run some backup software on a machine where a teacher regularly logs in. The teacher account is a power user, and the software only runs automatically when logged in as an admin, otherwise it forgets it's settings.

 

Many thanks.

Posted

If you have any experience of Group Policy, you can do it using this!

Create a new group policy object called: Local Staff Admin Account or similiar..

Alter the settings of this gpo to follows:

 

Computer Settings...

Security Settings...

Restricted Groups...

 

Add a new group called administrators, and add the Staff user account or group to it (if more than one user uses the computer).

 

If you have a domain administrator account or group of domain admin users who work on the network (e.g. techies), you will also need to add their specific group/usernames to the administrators group, you just created, otherwise their accounts will be locked down, when logging onto the machine as well.

 

HTH

Mark

  • Thanks 1
Posted

Forget group policy, it's overkill. Just use the computer management administrative tool on the local machine to add the user to the right group. (If you're doing this for 200 machines, by all means use GP, but it's a waste for just one.)

 

Edit: in fact, the method in post #2 will do this for all machines, not the single one you want.

  • Thanks 1
Posted

Thanks powdarrmonkey. Yes, I was thinking that I would have to put the single pc in a seperate OU to make the GPO method work. Is a definite solution, but will do it locally on the machine.

 

Thanks for your help.

Posted

You can filter GPO's by PC, Group or User... it doesn't have to apply toAuthenticated Users (ie: everyone & everything).

 

When you show it in the right pane from under Group Policy Objects in the GPMC, you remove "Authenticated Users" from the Security Filtering and either create your own group of computers it applies to, or list the computers in the filtering individually.

 

NB: Aren't Domain Admins automatically added into the Local Administrators group?

  • Thanks 1
Posted

NB: Aren't Domain Admins automatically added into the Local Administrators group?

 

Yes normally, if you don't specify anything under the group policy, but if you specify elevated privileges for a group or user, you also need to add your administrators/techies accounts.

 

HTH

Mark

  • Thanks 1
Posted
Surely you only need to grant access to the files/ folders and or reg keys for that particular software on the PC for domain users. Then any user logged into the PC will be able to run the backup software without risking making the user a full admin.
  • Thanks 1
Posted

Thanks for your replies. The user I wanted to grant access to wasn't a domain admin. I've added them to the local admin group via the computer management console- software seems to be running as if the user was an admin, so all ok!

 

Thanks for your suggestions:)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...