CommodoreS Posted September 18, 2012 Posted September 18, 2012 Using a Windows 2008 R2 server I would like to allow users to be able to Install Software locally on their computers, by using a GPO Policy. I have tried creating a GPO called "Local Admin Rights" and linking this to the OU which contains the machines. The settings are: Computer Config>Policies>Windows Settings>Security Settings>Restricted Groups Group Name: Domain\Local Admin Rights (Domain is actual domain name) This group is a member of: Administrators (I added builtin\administrators but when you go back into the GPO it only shows Administrators and the builtin\ part is missing) I have also added the Group "Local Admin Rights" to the users but this is not working. Users still cannot install software locally. I am wondering if there may be another setting somewhere that I am missing?
tmcd35 Posted September 18, 2012 Posted September 18, 2012 I've used GPO Preferences to do this. Computer/User -> Preferences -> Control Panel Settings -> Local Users and Groups I've added domain\staff_group to the local Administrators (built-in) group. Seems to work for me.
CommodoreS Posted September 18, 2012 Author Posted September 18, 2012 I will give that a go. Here is a more detailed guide of what I have tried: How to make Domain User as a Local Administrator for all PCs - TechNet Articles - United States (English) - TechNet Wiki
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now