Book now with code EOY2025
Claymoore wrote: » Let me start by saying that giving everyone administrator access to their PCs is a very bad idea.
blargoe wrote: » The Restricted Groups GPO will have a list of user SIDs that will be forced into the group that you specify. In this case I think you can't really use restricted groups, because the user is going to be dynamic, not determined until logon.
RobertKaucher wrote: » You would use "NT AUTHORITY\interactive". I would just add interactive to the local admins on *ONLY* the systems that required it. How many are we talking about? Is it a pain to configure?
RobertKaucher wrote: » Do you have a list of the IPs or the hostnames? You could script net local group using PSExec.
Devilsbane wrote: » You could simply go to each workstation and add domain users to the local administror group. This could be done via a script too to automate things (using the cacls command).
Devilsbane wrote: » Examples of how to add domain users to administrators or to use the cacls command?
RobertKaucher wrote: » You would use "NT AUTHORITY\interactive".
Use code EOY2025 to receive $250 off your 2025 certification boot camp!