I've wanted to accomplish exactly the same thing in several organizations I've worked with, and, unfortunately,...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
there isn't a good solution. You're left with several options, each of which isn't wholly satisfying:
- Add all users to the administrators group on every machine in your domain. This obviously raises security concerns as every user now has admin control over every computer.
- Create separate policies for each user in the organization. This is not a scalable solution!
- Use a middle-ground solution that divides computers into Active Directory Organizational Units (OUs) and assigns rights based upon OU membership. You'll still have the same security concerns as the first option, but it's a little more workable, as an individual's admin rights are limited to systems in the OU.
Let's all hope that Microsoft does something to address this in a future version of Group Policy!
For more information:
- Do the Group Policy Object and 'Password Never Expires' flag interact? Read more.
- Learn about the pros and cons of using stand-alone authentication that is not Active Directory-based.
Dig Deeper on Active Directory and LDAP Security
Related Q&A from Mike Chapple
A proposed cyberattack information database in the U.K. aims to improve cyberinsurance. Expert Mike Chapple explains what collecting data breach ...continue reading
The proposed CFTC regulations on cybersecurity testing are set to finalize in 2016. Expert Mike Chapple discusses the effects these regulations have ...continue reading
Whether Apple is a HIPAA covered entity was called into question when it advertised for a health regulations lawyer. Expert Mike Chapple discusses ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.