I need to use a GPO or script to ...

Billzie7718

Senior member
Sep 2, 2005
649
0
0
I have heard before that, during a domain logon, you can have the name of the user that is currently loggin on dropped into the local admin group. It then pulls them back out when they log off. It was either through GPO or VB script. Has anyone else done this?
 

Billzie7718

Senior member
Sep 2, 2005
649
0
0
Bump.

There must be someone doing this out there. Is everyone just adding "Domain Users" and calling it done? Does no one have a problem with EVERY domain user having FULL access to every other machine on the domain?
 

KB

Diamond Member
Nov 8, 1999
5,401
386
126
A login script that runs as the current user won't be able to add the current user to the Admin group because they won't have Admin rights to do the adding. So I know of no script to do it.

I have used the directions from the link you provided to add custom groups to the local administrators group. Although I prefer to let only IT be local administrators: what is the problem of having every domain user having full rights to every other machine on the domain, if you let them login and get full rights anyway?
Just make sure your servers don't have the GPO applied to add users to the local administrators.
 

Billzie7718

Senior member
Sep 2, 2005
649
0
0
First, I was actually referring to a Computer Configuration GPO, not User Configuration. This way, as long as the computer is a member of the domain, whoever logs on has Local Admin rights. Though I agree that users shouldn't have local admin rights, unfortunately we use a third party application (one that cannot be run as a service) that requires admin rights to run.

Second, our domain consists of location based OU's. Because of this, adding Domain Users to the local admin group means that the new intern in shipping would be able to connect to the computer of the president of HR and browse files that may potentially contain salaries or other confidential information. By applying this theoretical GPO, it would instead drop that users account name into local admin, meaning they would have full rights but ONLY to that machine, and ONLY while they are logged onto it.
 

RebateMonger

Elite Member
Dec 24, 2005
11,588
0
0
Have you tried finding the Registry and Folder permissions required to make that troublesome application run without making everybody "Local Administrator"?
 

Billzie7718

Senior member
Sep 2, 2005
649
0
0
Originally posted by: RebateMonger
Have you tried finding the Registry and Folder permissions required to make that troublesome application run without making everybody "Local Administrator"?

We ARE currently testing but I'm afraid that the expectations are already set. If/When this is implemented, there will be a large influx of issues (presumably because they can no longer install their Yahoo Messenger or Google Toolbar) but this will cause surveys to drop and therefore bonuses to decrease. Having local admin is not a problem, granted I would prefer it be different, but our unattended install is pretty streamline and doesnt require much effort to wipe it out and start over if things get too bad. Simply looking for a solution that solves the problem without hitting me in the bonus.
 

RebateMonger

Elite Member
Dec 24, 2005
11,588
0
0
One option to prevent EVERYONE from being a Local Administrator on EVERY PC:

a) Create Computer OUs for the various computer groups. Put "sensitive" computers in a special group, where you'll manage the Local Administrator privilege manually.
b) Create Security Groups containing those users who will be automatically granted Local Administrator rights on the various PCs
b) Create a "Computer Logon Script" that will be run each time the PC logs onto the Domain (this is NOT the User Logon Script)
c) Content of Computer Logon Script:
Net LocalGroup Administrators "domain_name"\"security_group" /add
(where "domain_name" is the name of your domain and "security_group" is the name of a User Group being given Local Administrator rights.

Test the logon script from the Command Prompt on some PCs to make sure it does what you want.

d) Create Group Policies and link them to the desired Computer OUs.
e) In the new Group Policies, set the \Computer Configuration\Windows Settings\Scripts (Startup/Shutdown) to automatically run the appropriate logon script that you've created
---------------------------------------------------------

The above will:
Make certain User Groups Local Administrators on all PCs in the selected Computer OU.
Will not "restrict" additional Local Administrators from being added if necessary.
Will NOT allow the User Groups to be Local Administrators on "sensitive" computers.
(You can add your own Local Administrators manually on the "sensitive" computers.)

I'd first do this on a small scale and verify it does what you want. And, obviously, test the final result to make sure that those "sensitive" PCs really are excluded.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |