Computing.Net > Forums > Networking > Local Rights vis Domain Rights

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Local Rights vis Domain Rights

Reply to Message Icon

Name: Jim
Date: September 12, 2002 at 19:31:47 Pacific
OS: XP
CPU/Ram: 1.6 GHz 512MB
Comment:

I am the network administrator for the Deapartment of Theatre at a university. We operate a lab with a wide variety if software and a large number of users.
Each machine is a member of the domain (Windows 2000 advanced server). I have user accounts setup on the server for everyone.

However if I don't setup a local and domain account on each machine the local rights aren't granted. This means that I have to setup 80 plus accounts on each machine. Inconvienient at best.

Is there some way to use the domain accounts to supply local rights, or even to copy the user accounts from the server to the local machine.

Anything would help.

Thanx



Sponsored Link
Ads by Google

Response Number 1
Name: Jennifer
Date: September 13, 2002 at 04:53:08 Pacific
Reply:

What do you mean by "Local rights aren't granted?" Are you trying to give the Domain Users Local Admin rights? If so, you need to add each user's Domain User account to the LOCAL Admin Group on each machine.

Or, if you're installing images, you could add "Authenticated" or "Domain" users to that Group. Of course, that would give everyone Local Admin, which isn't a good idea.


0

Response Number 2
Name: mike
Date: September 13, 2002 at 09:00:47 Pacific
Reply:

I'm not sure I understand what you are asking either, try reprhasing it.


0

Response Number 3
Name: dan
Date: September 13, 2002 at 09:40:54 Pacific
Reply:

Jim- what kind of "local rights" do mean? Do you want users to have local admin rights so they can install software? What I run into a lot is the change time thing, in order to grant a domain user the right to change time on the workstation, you do have to go to every machine and set that.


0

Response Number 4
Name: Jim
Date: September 13, 2002 at 13:48:21 Pacific
Reply:

Sorry for the lack of clearity. As Jennifer suggests above I am trying to give the Domain Users, Local Admin or user rights based on their domain account.

The local machines are running Windows XP. Is there a way to copy all of the accounts from the DC to each local Admin or User group with out having to type in all of the user accouts at every system?

Thank for your help so far!!


0

Response Number 5
Name: Glen
Date: September 13, 2002 at 19:20:09 Pacific
Reply:

"Is there a way to copy all of the accounts from the DC to each local Admin or User group with out having to type in all of the user accouts at every system?" - I have to ask, Why in the world would you want to? This defeats the purpose of having the domain in the first place.

I certainly would not give all users admin rights to all pc's. I can't imaging why you would want to but since you didn't ask advice on that I'll just say this. Anytime you find yourself doing something as tedious as this would be, remind yourself that there probably is a better way. Which I imagine is the very reason you are here right? If you do in fact want to go ahead with this, just create a group that contains the user accounts you want, and add that single group to local admins. You could even create a startup script through group policy (not a logon script) that would do this automatically.

Let say you create a group called TEST that holds all the desired users. If you want that group to be added to the local admin group of all the pcs create a startup script such as " net localgroup Administrators "TEST" /add ". (no beginning and ending quotes but include the quote around TEST.

Good luck. I'd still be curious why you want to do this though. ;)


0

Related Posts

See More



Response Number 6
Name: Jim
Date: September 14, 2002 at 17:21:00 Pacific
Reply:

Thanks everyone for your help!!!!

The resason I'm asking this is because currently if I don't have a local and Domain account of each user on each system users don't get access privliges that they need.

For example AutoCAD needs write priviliges to the registery if the user doesn't have those privileges the program fails. If I don't have an account for the user granting those privilages I get a lot of grumpy users.

If I understand you correctly I can copy some of my current domain groups to each individual system and resolve the problem.

This is the first group that I have talked to that has been able to give me a clue.

Thanks again!!!!


0

Response Number 7
Name: Paul H
Date: September 14, 2002 at 19:56:52 Pacific
Reply:

You can add all users requiring access to Autocad to a domain group "AutocadUsers" then add this domain group to the local admin group.


0

Response Number 8
Name: Jennifer
Date: September 23, 2002 at 10:04:20 Pacific
Reply:

There are also Registry fixes for AutoCad. Go to the Autodesk website, and they have the instructions for the Registry keys and file permissions you need to change.

Giving Admin rights to all users is a BAD idea.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Networking Forum Home


Sponsored links

Ads by Google


Results for: Local Rights vis Domain Rights

NT Can't logon to new domain www.computing.net/answers/networking/nt-cant-logon-to-new-domain/25448.html

Migrate local account to domain acc www.computing.net/answers/networking/migrate-local-account-to-domain-acc/15759.html

mapping drive of win server 2003 www.computing.net/answers/networking/mapping-drive-of-win-server-2003/36378.html