Domain User Has Local Admin Rights
I am a member of the domain admins group on my w2k3 server dc when i login to my new windows 7 enterprise machine with my domain admin account i have no local admin rights.
Domain user has local admin rights. Log on as a user with local administrative rights note. Tried copying the domain administrator user account same results. Used for very limited tasks that actually require da access. Remotely login to the user s workstation as a domain admin or physically sit in front of the user s windows pc.
I m in an unusual predicament in that there is no account i can use to add local admin rights to a computer with the exception of the administrator account which is disabled. This does not work on xp home right click the my computer icon. Besides godoftcp s main goal is to purge all local admins groups not necessarily knowing who s there for this purpose it s far better to use gpo preferences computer conf preferences control panel settings local users and groups set it up like in picture below and all users will get. This account is not a domain admin and is not an admin on any workstations.
Created domain admin user copying permissions that the built in domain administrator user account has. From the local users and groups snap in browse to groups double click on the administrators group locate your domain user account grant him her membership to the administrators. Used for administering end user workstations. This account is not a domain admin and is not an admin on any servers.
Win r lusrmgr msc. This is by far the preferred method limited to the cases when it is absolutely necessary to do so as it only gives the minimum amount of permissions required to reach the goal. Increase the permissions of the domain user on the local pc by adding the user in question in the local machine s power users or administrators group. Verified that domain admin group was listed in the local administrators group.
This tool is cool as long as all user machines are online at scan time while it s not always possible. The my computer will be displayed either on the desktop or start panel. Used for logging into servers.