Announcement

Collapse
No announcement yet.

Domain Users Local Admin

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Domain Users Local Admin

    If using Server 2008 R2 and Windows 7 and newer machines, is restricted groups still the best way of giving domain users local administrative rights? Or is there a newer way, given all the administrative templates built into Windows Server 2008 R2 and newer?

  • #2
    Re: Domain Users Local Admin

    Is there a specific reason you want to make the users local admins? That answer may help provide a better solution.
    1 1 was a racehorse.
    2 2 was 1 2.
    1 1 1 1 race 1 day,
    2 2 1 1 2

    Comment


    • #3
      Re: Domain Users Local Admin

      Originally posted by biggles77 View Post
      Is there a specific reason you want to make the users local admins? That answer may help provide a better solution.
      Yes, they have to be local admins to run the software we are running. I know it's not a best practice, but it's a necessary evil.

      Comment


      • #4
        Re: Domain Users Local Admin

        IMHO Restricted groups are still the best way, but be aware they can remove all existing local admin accounts, so make sure you don't lock yourself out!
        Tom Jones
        MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
        PhD, MSc, FIAP, MIITT
        IT Trainer / Consultant
        Ossian Ltd
        Scotland

        ** Remember to give credit where credit is due and leave reputation points where appropriate **

        Comment

        Working...
        X