Gabriel O. Franca
2017-Apr-03 14:14 UTC
[Samba] GPO administration right on the station for ordinary user
Good morning people, I need a help with a gpo to give administration right only on the workstation for a normal user. I tried 3 tutorials I found on google plus none worked. How do you do when you need an ordinary user to have administration right only on the workstation? If you have a tutorial that is running in version 4.5.5 and can make it available thank you very much. Regards, Gabriel Franca
L.P.H. van Belle
2017-Apr-03 14:22 UTC
[Samba] GPO administration right on the station for ordinary user
1ste google search. https://social.technet.microsoft.com/wiki/contents/articles/7833.how-to-make-a-domain-user-the-local-administrator-for-all-pcs.aspx try it and report back. This should work, i use the same for my remote desktop users. Greetz, Louis> -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens Gabriel O. Franca > via samba > Verzonden: maandag 3 april 2017 16:14 > Aan: samba > Onderwerp: [Samba] GPO administration right on the station for ordinary > user > > Good morning people, > > I need a help with a gpo to give administration right only on the > workstation for a normal user. > > I tried 3 tutorials I found on google plus none worked. > > How do you do when you need an ordinary user to have administration > right only on the workstation? > > If you have a tutorial that is running in version 4.5.5 and can make it > available thank you very much. > > Regards, > > Gabriel Franca > > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba
Gabriel O. Franca
2017-Apr-03 14:26 UTC
[Samba] GPO administration right on the station for ordinary user
thank you so much, At the end of the afternoon I will implement and I will inform you again if it worked. Regards, Gabriel Franca Em 03/04/2017 11:22, L.P.H. van Belle escreveu:> 1ste google search. > > https://social.technet.microsoft.com/wiki/contents/articles/7833.how-to-make-a-domain-user-the-local-administrator-for-all-pcs.aspx > > try it and report back. > This should work, i use the same for my remote desktop users. > > > Greetz, > > Louis > > > >> -----Oorspronkelijk bericht----- >> Van: samba [mailto:samba-bounces at lists.samba.org] Namens Gabriel O. Franca >> via samba >> Verzonden: maandag 3 april 2017 16:14 >> Aan: samba >> Onderwerp: [Samba] GPO administration right on the station for ordinary >> user >> >> Good morning people, >> >> I need a help with a gpo to give administration right only on the >> workstation for a normal user. >> >> I tried 3 tutorials I found on google plus none worked. >> >> How do you do when you need an ordinary user to have administration >> right only on the workstation? >> >> If you have a tutorial that is running in version 4.5.5 and can make it >> available thank you very much. >> >> Regards, >> >> Gabriel Franca >> >> >> -- >> To unsubscribe from this list go to the following URL and read the >> instructions: https://lists.samba.org/mailman/options/samba >
Marc Muehlfeld
2017-Apr-03 14:49 UTC
[Samba] GPO administration right on the station for ordinary user
Hi Gabriel, Am 03.04.2017 um 16:14 schrieb Gabriel O. Franca via samba:> I need a help with a gpo to give administration right only on the > workstation for a normal user.This is strictly speaking not a Samba question. However, I documented this in the past, because I thought that a lot of admins might have this question when setting up a Samba AD: https://wiki.samba.org/index.php/Managing_local_groups_on_domain_members_via_GPO_restricted_groups Regards, Marc
L.P.H. van Belle
2017-Apr-03 15:01 UTC
[Samba] GPO administration right on the station for ordinary user
Hai Marc, But thats missing info.. :-( Maybe its also a good thing to add just after the first picture on the wiki. That the security filter on the GPO MUST have "authenticated users" or Domain computer group. You decide. Greetz, Louis> -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens Marc Muehlfeld > via samba > Verzonden: maandag 3 april 2017 16:49 > Aan: Gabriel O. Franca; samba > Onderwerp: Re: [Samba] GPO administration right on the station for > ordinary user > > Hi Gabriel, > > Am 03.04.2017 um 16:14 schrieb Gabriel O. Franca via samba: > > I need a help with a gpo to give administration right only on the > > workstation for a normal user. > > This is strictly speaking not a Samba question. > > However, I documented this in the past, because I thought that a lot of > admins might have this question when setting up a Samba AD: > > https://wiki.samba.org/index.php/Managing_local_groups_on_domain_members_v > ia_GPO_restricted_groups > > > Regards, > Marc > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba
Marc Muehlfeld
2017-Apr-03 15:21 UTC
[Samba] GPO administration right on the station for ordinary user
Hi Louis, Am 03.04.2017 um 17:01 schrieb L.P.H. van Belle via samba:> But thats missing info.. :-( > > Maybe its also a good thing to add just after the first picture on the wiki. > That the security filter on the GPO MUST have "authenticated users" or Domain computer group. > You decide.thanks for bringing this up. I will verify this later. I'm 85% sure, I never set a security filter on GPOs. On the other side, it's more than 2 years ago that I wrote this doc and even longer that I implemented restricted groups in a production AD. So it's possible that I'm wrong. :-) I looked at some other guides online that describe restricted groups, but none (incl. the one you posted in this thread) tells about changing the default filter settings. Why do I need this filter and what happens if I don't set it? Regards, Marc
L.P.H. van Belle
2017-Apr-04 06:21 UTC
[Samba] GPO administration right on the station for ordinary user
Hai Marc, Well first, no you did nothing wrong here. This was fine when you wrote it, but after the BadLock Bug, Microsoft change the way some policies are applied. A good explaination here. http://www.mistercloudtech.com/2016/06/22/june-14th-windows-update-changes-group-policy-security-filtering/ Best regards, Louis> -----Oorspronkelijk bericht----- > Van: Marc Muehlfeld [mailto:mmuehlfeld at samba.org] > Verzonden: maandag 3 april 2017 17:22 > Aan: L.P.H. van Belle; samba at lists.samba.org > Onderwerp: Re: [Samba] GPO administration right on the station for > ordinary user > > Hi Louis, > > Am 03.04.2017 um 17:01 schrieb L.P.H. van Belle via samba: > > But thats missing info.. :-( > > > > Maybe its also a good thing to add just after the first picture on the > wiki. > > That the security filter on the GPO MUST have "authenticated users" or > Domain computer group. > > You decide. > > thanks for bringing this up. I will verify this later. > > I'm 85% sure, I never set a security filter on GPOs. On the other side, > it's more than 2 years ago that I wrote this doc and even longer that I > implemented restricted groups in a production AD. So it's possible that > I'm wrong. :-) > > I looked at some other guides online that describe restricted groups, > but none (incl. the one you posted in this thread) tells about changing > the default filter settings. > > Why do I need this filter and what happens if I don't set it? > > Regards, > Marc
Possibly Parallel Threads
- GPO administration right on the station for ordinary user
- GPO administration right on the station for ordinary user
- GPO administration right on the station for ordinary user
- GPO Filter Group/User
- GPOs: only Default Domain Policy is being applied, ohers are ignored