Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I am the network administrator for the Deapartment of Theatre at a university. We operate a lab with a wide variety if software and a large number of users.
Each machine is a member of the domain (Windows 2000 advanced server). I have user accounts setup on the server for everyone.However if I don't setup a local and domain account on each machine the local rights aren't granted. This means that I have to setup 80 plus accounts on each machine. Inconvienient at best.
Is there some way to use the domain accounts to supply local rights, or even to copy the user accounts from the server to the local machine.
Anything would help.
Thanx

What do you mean by "Local rights aren't granted?" Are you trying to give the Domain Users Local Admin rights? If so, you need to add each user's Domain User account to the LOCAL Admin Group on each machine.
Or, if you're installing images, you could add "Authenticated" or "Domain" users to that Group. Of course, that would give everyone Local Admin, which isn't a good idea.

Jim- what kind of "local rights" do mean? Do you want users to have local admin rights so they can install software? What I run into a lot is the change time thing, in order to grant a domain user the right to change time on the workstation, you do have to go to every machine and set that.

Sorry for the lack of clearity. As Jennifer suggests above I am trying to give the Domain Users, Local Admin or user rights based on their domain account.
The local machines are running Windows XP. Is there a way to copy all of the accounts from the DC to each local Admin or User group with out having to type in all of the user accouts at every system?
Thank for your help so far!!

"Is there a way to copy all of the accounts from the DC to each local Admin or User group with out having to type in all of the user accouts at every system?" - I have to ask, Why in the world would you want to? This defeats the purpose of having the domain in the first place.
I certainly would not give all users admin rights to all pc's. I can't imaging why you would want to but since you didn't ask advice on that I'll just say this. Anytime you find yourself doing something as tedious as this would be, remind yourself that there probably is a better way. Which I imagine is the very reason you are here right? If you do in fact want to go ahead with this, just create a group that contains the user accounts you want, and add that single group to local admins. You could even create a startup script through group policy (not a logon script) that would do this automatically.
Let say you create a group called TEST that holds all the desired users. If you want that group to be added to the local admin group of all the pcs create a startup script such as " net localgroup Administrators "TEST" /add ". (no beginning and ending quotes but include the quote around TEST.
Good luck. I'd still be curious why you want to do this though. ;)

Thanks everyone for your help!!!!
The resason I'm asking this is because currently if I don't have a local and Domain account of each user on each system users don't get access privliges that they need.
For example AutoCAD needs write priviliges to the registery if the user doesn't have those privileges the program fails. If I don't have an account for the user granting those privilages I get a lot of grumpy users.
If I understand you correctly I can copy some of my current domain groups to each individual system and resolve the problem.
This is the first group that I have talked to that has been able to give me a clue.
Thanks again!!!!

You can add all users requiring access to Autocad to a domain group "AutocadUsers" then add this domain group to the local admin group.

There are also Registry fixes for AutoCad. Go to the Autodesk website, and they have the instructions for the Registry keys and file permissions you need to change.
Giving Admin rights to all users is a BAD idea.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |