Ask the Expert

How to edit group policy objects to give a user local admin rights

I want to be able to give a user rights (power user or admin) to his or her local computer and only his or her local computer. Can this be accomplished through Group Policy objects? If so, would it require a policy for each computer?

    Requires Free Membership to View

I've wanted to accomplish exactly the same thing in several organizations I've worked with, and, unfortunately, there isn't a good solution. You're left with several options, each of which isn't wholly satisfying:

  • Add all users to the administrators group on every machine in your domain. This obviously raises security concerns as every user now has admin control over every computer.
  • Create separate policies for each user in the organization. This is not a scalable solution!
  • Use a middle-ground solution that divides computers into Active Directory Organizational Units (OUs) and assigns rights based upon OU membership. You'll still have the same security concerns as the first option, but it's a little more workable, as an individual's admin rights are limited to systems in the OU.

Let's all hope that Microsoft does something to address this in a future version of Group Policy!

For more information:

This was first published in July 2009

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: