1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Permission On Windows Xp

Discussion in 'Windows Home Server' started by Jason, Aug 25, 2009.

  1. Jason

    Jason Guest

    Hi

    I have just taken over an it support contract The company has windows server
    dc 2003 with around 50 pc connect the os is windows xp is there an easy way
    of reset all permission? I have looked @ about 10 computers some users have
    admin right some do not is there an easy way of listing out user with admion
    rights or do i delete the local account on the pc?
     
  2. "Jason" <Jason@hotmaial.com> wrote in message
    news:egBAXzYJKHA.4168@TK2MSFTNGP05.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Hi
    >
    > I have just taken over an it support contract The company has windows
    > server dc 2003 with around 50 pc connect the os is windows xp is there an
    > easy way of reset all permission? I have looked @ about 10 computers some
    > users have admin right some do not is there an easy way of listing out
    > user with admion rights or do i delete the local account on the pc?
    ><!--colorc--><!--/colorc-->


    Are you asking about removing users from having Local Admin Rights on the
    local machines? If so, one way of doing it is use Restricted Groups in a
    GPO.

    ==================================================================
    Restricted Groups

    (You'll need to do this from a non-DC with the GPMC installed because you
    need access to local groups on a non-DC)

    Going on memory... forgive me if I missed a step...
    In D, create an OU and call it Restricted Groups (or whatever you want to
    call it)
    In AD, create a group and call it Local Power Users Group
    Create another group and call it Local Admin Users Group
    Logon as domain admin on an XP machine
    Install the GPMC on an XP machine
    Open the GPMC and navigate to the OU you created above
    Create and link a new GPO to the OU
    Right-click on it and choose Edit
    Navigate to the Computer section, and Restricted Groups
    Choose new group, browse to the domains' Local Power Users Group and add it
    to the local XP machine's groups, and choose Power Users
    Choose new group, browse to the ldomain's Local Admin Users Group and add it
    to the local XP machine's groups and choose Administrators
    Move the computer to the OU
    Add the user to the Local Power Users Group in AD that you created above
    On the machine where the user is logged on, have him logoff and logon
    May have to have him do it twice
    In the XP's computer Management console, look at the Local Power Users and
    Administrators Groups and see if the Domain\Local Power Users Group is added
    to the machine's local Power Users group and the Local Admin Users Group is
    added to the machine';s local Administrators group. If so, they will show up
    as grayed out, meaning the policy is working. If you added the user to the
    domain's Local Power Users Group, then the user should now be able to
    perform actions of a Power User.

    ------
    Related Links:

    Using Restricted Groups


    Restricted groups are made for that:


    ------
    You can also use Group Policy Preferences:

    You can take advantage of the Local Users and Groups settings of Group
    Policy Preferences, which gives you an option to add the current user to an
    arbitrary local group (including local Administrators). For more info, refer
    to

    ==================================================================

    --
    Ace

    This posting is provided "AS-IS" with no warranties or guarantees and
    confers no rights.

    Please reply back to the newsgroup or forum for collaboration benefit among
    responding engineers, and to help others benefit from your resolution.

    Ace Fekay, MCT, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA Messaging
    Microsoft Certified Trainer

    For urgent issues, please contact Microsoft PSS directly. Please check
    for regional support phone numbers.
     
  3. Jason

    Jason Guest

    Cheers that looks ace


    "Ace Fekay [MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message
    news:OgyBMSZJKHA.1336@TK2MSFTNGP05.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > "Jason" <Jason@hotmaial.com> wrote in message
    > news:egBAXzYJKHA.4168@TK2MSFTNGP05.phx.gbl...<!--coloro:green--><span style="color:green <!--/coloro-->
    >> Hi
    >>
    >> I have just taken over an it support contract The company has windows
    >> server dc 2003 with around 50 pc connect the os is windows xp is there an
    >> easy way of reset all permission? I have looked @ about 10 computers some
    >> users have admin right some do not is there an easy way of listing out
    >> user with admion rights or do i delete the local account on the pc?
    >><!--colorc--><!--/colorc-->
    >
    >
    > Are you asking about removing users from having Local Admin Rights on the
    > local machines? If so, one way of doing it is use Restricted Groups in a
    > GPO.
    >
    > ==================================================================
    > Restricted Groups
    >
    > (You'll need to do this from a non-DC with the GPMC installed because you
    > need access to local groups on a non-DC)
    >
    > Going on memory... forgive me if I missed a step...
    > In D, create an OU and call it Restricted Groups (or whatever you want to
    > call it)
    > In AD, create a group and call it Local Power Users Group
    > Create another group and call it Local Admin Users Group
    > Logon as domain admin on an XP machine
    > Install the GPMC on an XP machine
    > Open the GPMC and navigate to the OU you created above
    > Create and link a new GPO to the OU
    > Right-click on it and choose Edit
    > Navigate to the Computer section, and Restricted Groups
    > Choose new group, browse to the domains' Local Power Users Group and add
    > it to the local XP machine's groups, and choose Power Users
    > Choose new group, browse to the ldomain's Local Admin Users Group and add
    > it to the local XP machine's groups and choose Administrators
    > Move the computer to the OU
    > Add the user to the Local Power Users Group in AD that you created above
    > On the machine where the user is logged on, have him logoff and logon
    > May have to have him do it twice
    > In the XP's computer Management console, look at the Local Power Users and
    > Administrators Groups and see if the DomainLocal Power Users Group is
    > added to the machine's local Power Users group and the Local Admin Users
    > Group is added to the machine';s local Administrators group. If so, they
    > will show up as grayed out, meaning the policy is working. If you added
    > the user to the domain's Local Power Users Group, then the user should now
    > be able to perform actions of a Power User.
    >
    > ------
    > Related Links:
    >
    > Using Restricted Groups
    >
    >
    > Restricted groups are made for that:
    >

    >
    > ------
    > You can also use Group Policy Preferences:
    >
    > You can take advantage of the Local Users and Groups settings of Group
    > Policy Preferences, which gives you an option to add the current user to
    > an
    > arbitrary local group (including local Administrators). For more info,
    > refer
    > to

    > ==================================================================
    >
    > --
    > Ace
    >
    > This posting is provided "AS-IS" with no warranties or guarantees and
    > confers no rights.
    >
    > Please reply back to the newsgroup or forum for collaboration benefit
    > among responding engineers, and to help others benefit from your
    > resolution.
    >
    > Ace Fekay, MCT, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA Messaging
    > Microsoft Certified Trainer
    >
    > For urgent issues, please contact Microsoft PSS directly. Please check
    >
    for regional support phone numbers. <!--colorc--><!--/colorc-->
     
  4. "Jason" <Jason@hotmaial.com> wrote in message
    news:epSEHoZJKHA.1492@TK2MSFTNGP03.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Cheers that looks ace<!--colorc--><!--/colorc-->

    You are welcome!

    Ace
     

Share This Page