Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active directory permissions question

Status
Not open for further replies.

Theo2k

Technical User
Dec 19, 2002
143
US
Greetings,

What permissions should I assign to a users in order to install applications on his workstation without having full access to my AD 2003?

When I give him Administrator rights still can't install apps - but with enterpise domain right there is not a problem.

Thank you for any clarification.

 
I think your problem is the workstation's user account, not the domain permissions. A standard SBS User profile, with Admin privileges on his desktop, should be able to install apps to the desktop, not to the server!

If in doubt, disconnect the workstation from the domain & login the user. Can you install apps? If not logout then login as local admin and change the settings on the user account. BTW, what OS is the workstation?

Tony

Users helping Users...
 
Same problem! The user's permissions on the AD are: (domain user - administrators). I disconnected the laptop from the network and logged in same results.
 
Go to control panel on the client PC, Users, add the domain user's account to the PC as a Local Admin.
 
Theo2k,

The user's permissions on AD have nothing to do with the level of his/her account on the client PC. If we use XP as an example, a fresh logon to a new domain will automatically assign that user (regardless of their AD perm level) a limited account...it will appear as C:\Documents and Settings\User.DOMAIN.

Like myself and noveyron have stated, you need to logon on to the LOCAL CLIENT PC as ADMINISTRATOR (underneath Administrator in the logon box there will be "More Options" that select between the Domain and "This PC", choose the latter) and change the User Account (User.DOMAIN) to Admin level. Not just "User", but "User.DOMAIN". Then logoff, re-logon as the User in the correct Domain and you should be able to have your way with the client PC, whether connected to the AD Domain or not.

Remember to go back into the AD and change the User back to a standard SBS User, you don't want ANYONE with Admin privileges except the Domain Admin!

Even then, if the Domain Admin has not been set up as an Admin by the Local Admin, they will have a limited account on the client. This is a good default behavior. When you're done, delete all the extraneous profiles from C:\Documents and Settings.

Tony

Tony

Users helping Users...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top