[452] in winnt
Re: Admin privs restricted to workstation in domain
daemon@ATHENA.MIT.EDU (Tom Fitzgerald)
Thu Dec 9 20:59:52 1999
Message-Id: <199912100159.UAA22336@sligo.mit.edu>
To: Don Nelson <dnelson@psfc.MIT.EDU>
cc: ntpartners@MIT.EDU
In-Reply-To: Your message of "Thu, 09 Dec 1999 19:43:15 EST."
<4.2.0.58.19991209193314.00aba520@psfc.mit.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Date: Thu, 09 Dec 1999 20:59:39 -0500
From: Tom Fitzgerald <tfitz@MIT.EDU>
> Is there any way to give full admin privileges to the owner of a PC that is
> a member of an NT4 domain, so that that person can do anything he/she
> pleases with his/her own PC, but restrict that person so that he/she cannot
> use domain management tools and cannot touch the C$ hidden shares of any
> other PC in the domain?
Sure - on the workstation:
User Manager, doubleclick on Administrators group (bottom pane), click Add,
List names from <domain>, pick user to add, click Add, and OK.
This doesn't give any privs outside the workstation it's done on.
But why not give the user the administrator password? It's not really
any different, except for the hassle of logging out and logging back
in again, and (if the user is conscientious), can avoid much damage
caused by mistakes.
> We are looking for an answer to the same question for Windows 2000 domains.
Can't help there, but I'd assume it would be similar.