[456] in winnt
Re: Admin privs restricted to workstation in domain
daemon@ATHENA.MIT.EDU (bcvernon@MIT.EDU)
Mon Dec 13 11:07:07 1999
From: bcvernon@MIT.EDU
Message-Id: <9912131606.AA07740@MIT.EDU>
Date: Mon, 13 Dec 1999 11:09:02 -0500
To: Don Nelson <dnelson@psfc.mit.edu>
Cc: ntpartners@MIT.EDU
In-Reply-To: <4.2.0.58.19991209193314.00aba520@psfc.mit.edu>
Mime-Version: 1.0
Content-Type: multipart/alternative;
types="text/plain,text/html";
boundary="=====================_1212496203==_.ALT"
--=====================_1212496203==_.ALT
Content-Type: text/plain; charset="us-ascii"
Hi,
You can make that person's domain account an administrator of his local
machine. Simply launch the user manager on his machine and open the
administrators group. Go through the process to add a user to the group,
choosing the domain database, instead of the local computer database, from
which to choose the account to add. Add his domain account to the local
administrators group, and now you are done. He will only have full admin
priviledges on his own computer. If you have any questions, please feel free
to ask.
Take Care,
Bryant C. Vernon
At 07:43 PM 12/9/99 -0500, you wrote:
>Is there any way to give full admin privileges to the owner of a PC that is
>a member of an NT4 domain, so that that person can do anything he/she
>pleases with his/her own PC, but restrict that person so that he/she cannot
>use domain management tools and cannot touch the C$ hidden shares of any
>other PC in the domain?
>
>We are looking for an answer to the same question for Windows 2000 domains.
>
Bryant C. Vernon, Consultant
MIT Departmental Computing Support
E40-327, 77 Massachusetts Avenue, Cambridge, MA 02139
Phone: (617) 253-5103
Email: bcvernon@mit.edu, Web site:
<http://bcvernon.mit.edu>http://bcvernon.mit.edu
--=====================_1212496203==_.ALT
Content-Type: text/html; charset="us-ascii"
<html><div>Hi,</div>
<br>
<div>You can make that person's domain account an administrator of his
local machine. Simply launch the user manager on his machine and
open the administrators group. Go through the process to add
a user to the group, choosing the domain database, instead of the
local computer database, from which to choose the account to add.
Add his domain account to the local administrators group, and now you are
done. He will only have full admin priviledges on his own
computer. If you have any questions, please feel free to
ask.</div>
<br>
<div>Take Care,</div>
<div>Bryant C. Vernon</div>
<br>
<br>
<div>At 07:43 PM 12/9/99 -0500, you wrote:</div>
<div>>Is there any way to give full admin privileges to the owner of a
PC that is </div>
<div>>a member of an NT4 domain, so that that person can do anything
he/she </div>
<div>>pleases with his/her own PC, but restrict that person so that
he/she cannot </div>
<div>>use domain management tools and cannot touch the C$ hidden
shares of any </div>
<div>>other PC in the domain?</div>
<div>></div>
<div>>We are looking for an answer to the same question for Windows
2000 domains.</div>
>
<br>
<x-html>Bryant C. Vernon, Consultant <BR>
<b><font color="#800000">MIT</font></b> Departmental Computing Support
<BR>
E40-327, 77 Massachusetts Avenue, Cambridge, MA 02139 <BR>
Phone: (617) 25<b><font color="#800000">3-5103 <BR>
</font></b>Email:
<b><font color="#000080">bcvernon@mit.edu</font></b>, Web site:
<A HREF="http://bcvernon.mit.edu">http://bcvernon.mit.edu</A> <BR>
</x-html>
--=====================_1212496203==_.ALT--