[454] in winnt

home help back first fref pref prev next nref lref last post

Re: Admin privs restricted to workstation in domain

daemon@ATHENA.MIT.EDU (David S. Woodruff)
Fri Dec 10 10:33:39 1999

Date: Fri, 10 Dec 1999 10:31:23 -0500 (EST)
From: "David S. Woodruff" <dsw@mitlns.mit.edu>
To: Don Nelson <dnelson@psfc.mit.edu>
Cc: NT Partners at MIT <ntpartners@MIT.EDU>
In-Reply-To: <4.2.0.58.19991209193314.00aba520@psfc.mit.edu>
Message-Id: <Pine.OSF.4.05.9912101018440.20004-100000@pequod.mit.edu>
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

Hi Don,

On Thu, 9 Dec 1999, Don Nelson wrote:

> Is there any way to give full admin privileges to the owner of a PC that is 
> a member of an NT4 domain, so that that person can do anything he/she 
> pleases with his/her own PC, but restrict that person so that he/she cannot 
> use domain management tools and cannot touch the C$ hidden shares of any 
> other PC in the domain?
> 

There is one possibility that I see... put the user in the local
administrators group and then use the Policy Editor to add apropriate
restrictions to the account.  Some things that can be restricted are
access to Network Neighborhood and the ability to map and disconnect
network drives.  

> We are looking for an answer to the same question for Windows 2000 domains.
> 

This should be easier to deal with since you will be able to create a
local group with restrictions that can be placed in the local
administrator's group.  At any rate, all NT 4.0 hooks and handle should be
available in W2000.

                      Dave

David S. Woodruff                   http://www.lns.mit.edu/~dsw
MIT Lab for Nuclear Science         Phone: (617)-253-6943
24-030g, MIT                        Email: dsw@mitlns.mit.edu
77 Massachusetts Avenue             FAX:  (617)-258-6591
Cambridge, MA, 02139                Call me Ishmael.


home help back first fref pref prev next nref lref last post