How to edit group policy objects to give a user local admin rights

How to edit group policy objects to give a user local admin rights

I want to be able to give a user rights (power user or admin) to his or her local computer and only his or her local computer. Can this be accomplished through Group Policy objects? If so, would it require a policy for each computer?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

I've wanted to accomplish exactly the same thing in several organizations I've worked with, and, unfortunately, there isn't a good solution. You're left with several options, each of which isn't wholly satisfying:

  • Add all users to the administrators group on every machine in your domain. This obviously raises security concerns as every user now has admin control over every computer.
  • Create separate policies for each user in the organization. This is not a scalable solution!
  • Use a middle-ground solution that divides computers into Active Directory Organizational Units (OUs) and assigns rights based upon OU membership. You'll still have the same security concerns as the first option, but it's a little more workable, as an individual's admin rights are limited to systems in the OU.

Let's all hope that Microsoft does something to address this in a future version of Group Policy!

For more information:

This was first published in July 2009