1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

admin rights for domain users

Discussion in 'Networking (Hardware & Software)' started by yohoooo, 2004/08/26.

Thread Status:
Not open for further replies.
  1. 2004/08/26
    yohoooo

    yohoooo Inactive Thread Starter

    Joined:
    2004/08/19
    Messages:
    6
    Likes Received:
    0
    Hi, how can i grant local computer admin rights to the domain users on the same computer? Please help, thanks.
     
  2. 2004/08/26
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Put their domain account into the local administrator group.
     
    Newt,
    #2

  3. to hide this advert.

  4. 2004/08/26
    Scott Smith

    Scott Smith Inactive Alumni

    Joined:
    2002/01/12
    Messages:
    1,950
    Likes Received:
    4
    Newt correct me if im wrong but the way I do it is like this:

    Log on to local machine as Domain Admin.

    Go to Control Panel / users and create a new user.

    Create the Domain User account on the local machine and select Administrator as the local user rights.

    Log off Domain admin and log back on as Domain User and your done.
     
  5. 2004/08/26
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    You are doing it the hard way unless you need the user to have admin rights when the PC is not on the network.

    For a user on domain bigplace with a username of funguy you would just need to open the administrator group on the PC and add bigplace\funguy to the group. Deed done. No need to create a local account.
     
    Newt,
    #4
  6. 2004/08/29
    Scott Smith

    Scott Smith Inactive Alumni

    Joined:
    2002/01/12
    Messages:
    1,950
    Likes Received:
    4
    I'm going to play with this today Newt.
    I may have to get back to you for the exact steps for both Win2k and XP.
     
  7. 2004/08/29
    Scott Smith

    Scott Smith Inactive Alumni

    Joined:
    2002/01/12
    Messages:
    1,950
    Likes Received:
    4
    Ok maybe I'm missing something here.

    Had a windows XP desktop with a local user account of Local-User in a workgroup of WORKGROUP

    The is already a Domin account called Local-User on the DC

    Joined the PC to the Domain and restarted.
    Logged on as DOMAIN\Local-User

    Now Local-User.domain has no privliges on the local machine. You with me so far?

    So log off, Log back on a Domain Administrator.
    Go to controll Paner / User Accounts
    Guess What? No Domain account for Domain\Local-User Exists! :rolleyes:

    So I add the Domain\Local-User and put him in the Administrators and all is well.

    What did I miss??
     
  8. 2004/08/30
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    You didn't miss much. Confusion with user accounts maybe.

    If you have accounts
    domain\Ima-user
    local-pc\Ima-user
    The account names all look the same to people, Ima-user, but to the network and to the PC they are completely different.

    The computer is reading the account's SID rather than the people-friendly display name.

    If you add domain\Ima-user to the PC's local administrator group then domain\Ima-user is an admin on that PC but local-pc\Ima-user is not unless the accounts is also added.

    If for some reason you later delete domain\Ima-user from the domain accounts and then add it back, the PC will be confused since the account it had as a local admin no longer exists. Same name but different SID so as far as the PC is concerned, completly different user account.

    You can easily test this yourself.
    - create a domain user account
    - add it to security for any folder on a PC and the username will show in the folder security display.
    - delete the domain user account
    - create a new one with the exact same name
    - now when you look at folder security there will be a string of numbers shown as an account in the security settings. It will be the SID of the now defunct account and is trash. The domain user account will be nowhere to be seen.
     
    Newt,
    #7
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.