[454] in winnt
Re: Admin privs restricted to workstation in domain
daemon@ATHENA.MIT.EDU (David S. Woodruff)
Fri Dec 10 10:33:39 1999
Date: Fri, 10 Dec 1999 10:31:23 -0500 (EST)
From: "David S. Woodruff" <dsw@mitlns.mit.edu>
To: Don Nelson <dnelson@psfc.mit.edu>
Cc: NT Partners at MIT <ntpartners@MIT.EDU>
In-Reply-To: <4.2.0.58.19991209193314.00aba520@psfc.mit.edu>
Message-Id: <Pine.OSF.4.05.9912101018440.20004-100000@pequod.mit.edu>
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Hi Don,
On Thu, 9 Dec 1999, Don Nelson wrote:
> Is there any way to give full admin privileges to the owner of a PC that is
> a member of an NT4 domain, so that that person can do anything he/she
> pleases with his/her own PC, but restrict that person so that he/she cannot
> use domain management tools and cannot touch the C$ hidden shares of any
> other PC in the domain?
>
There is one possibility that I see... put the user in the local
administrators group and then use the Policy Editor to add apropriate
restrictions to the account. Some things that can be restricted are
access to Network Neighborhood and the ability to map and disconnect
network drives.
> We are looking for an answer to the same question for Windows 2000 domains.
>
This should be easier to deal with since you will be able to create a
local group with restrictions that can be placed in the local
administrator's group. At any rate, all NT 4.0 hooks and handle should be
available in W2000.
Dave
David S. Woodruff http://www.lns.mit.edu/~dsw
MIT Lab for Nuclear Science Phone: (617)-253-6943
24-030g, MIT Email: dsw@mitlns.mit.edu
77 Massachusetts Avenue FAX: (617)-258-6591
Cambridge, MA, 02139 Call me Ishmael.