InterviewSolution
| 1. |
Solve : Make User Profile Local Admin on all stations? |
|
Answer» I know that a user can be added to the domain user group, but is it possible to add a user to a local admin group? so that they have full local admin rights on all workstations? I think our DC uses win 2k (just a guess though).If you create an admin account that is a roaming account, it can act as a local admin account when the workstations are off the net. But if you want to empower someone to be able to perform local admin access, but restrict them out of domain admin wide access, I'd set up a POWER user privileged account and in GP, I believe you can restrict the systems they have access to which restricts them to just the workstations vs being able to logon to servers and sensitive systems such as payroll and HR etc. If you create an admin account that is a roaming account, it can act as a local admin account when the workstations are off the net. But if you want to empower someone to be able to perform local admin access, but restrict them out of domain admin wide access, I'd set up a power user privileged account and in GP, I believe you can restrict the systems they have access to which restricts them to just the workstations vs being able to logon to servers and sensitive systems such as payroll and HR etc. We do use roaming profiles for most of the users (although not all I think). I really don't feel like making a new group though. LOL! If it was as simple as adding the user to an existing/default group, then I'd be down, but I'll probably just go with domain admin ANYWAY. I may actually just NEED to double check that my profile is roaming... :/ because I have set myself to local admin on several machines, but it never PERSISTS to new machines... so the DC obviously isn't passing it along. |
|