Local administrative access

I am trying to set up NT Workstations so that the user can have the rights to modify anything on the local machine (install apps, edit registry, change drivers,etc. ) like an administrator can. I do not want them to have admin rights on the network.

Windows Networking 2246 This topic was started by ,


data/avatar/default/avatar39.webp

163 Posts
Location -
Joined 2000-07-30
I am trying to set up NT Workstations so that the user can have the rights to modify anything on the local machine (install apps, edit registry, change drivers,etc.) like an administrator can. I do not want them to have admin rights on the network. Unless they log into the local machine as opposed to logging into the domain, I have not been able to implement this. Any ideas?
 
Thanks in advance.

Participate on our website and join the conversation

You have already an account on our website? Use the link below to login.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This topic is archived. New comments cannot be posted and votes cannot be cast.

Responses to this topic


data/avatar/default/avatar03.webp

90 Posts
Location -
Joined 2000-07-11
I had the same problem, I wanted some users to be able to burn CD's using Nero.... but for using Nero you must have administrator's rights, and that means logging as an admin! I have found no other mean to burn CD's under a user account than to use another burning program.... I don't know if the "Power User" has network capabilities, and, more important, their entity....probably you could investigate this. As for reducing the "power" of Local administrators, you have no way. They're Admins, Full Stop.

data/avatar/default/avatar08.webp

220 Posts
Location -
Joined 2000-05-09
usrmgr.exe (usermanager for domains) click, select domain - type in the host name of the machine - add the user to the administrators group..thatll make em member of the LOCAL admin group

data/avatar/default/avatar39.webp

163 Posts
Location -
Joined 2000-07-30
OP
I have tried something like that. I made them an admin on the local machine, and instead of logging into the domain they log into the local machine. if their password and username are the same, they can access the network resources as users but the local machine as "local admins". the problem is the network login script does not run in this manner. I had to set a script on each individual machine to run and access the system's loginscrips. I really do not like this solution, but it seems like the only way to accomplish what I need. Thank you anyway for the help.

data/avatar/default/avatar21.webp

3 Posts
Location -
Joined 2000-08-28
Hi
What you need to do is log onto the workstation as the domain administrator or the Workstaion administrator, start user manager on the workstation, add the domain member who will be using the Workstation to the local administrator group. This will give the user adminstrative rights to the workstation but not to the domain controllers.
 
------------------
PSM450
Brainbench ‘MVP’ for WinNT Workstation
http://www.brainbench.com

data/avatar/default/avatar21.webp

3 Posts
Location -
Joined 2000-08-28
Oops, double post.
------------------
PSM450
Brainbench ‘MVP’ for WinNT Workstation http://www.brainbench.com
 
 
[This message has been edited by PSM450 (edited 28 August 2000).]