Discussion on:

Message 34 of 72
0 Votes
+ -
RunAs
I'd certainly agree that using an OU structure with appropriate GPs is the way to go IF you're using Active Directory (storch didn't say one way or the other).

I might've only implied it, but if setup to use RunAs, each user would have TWO accounts - one as a User, and the other with "enhanced" permissions that can be setup using Local Policies or in AD as you advocate (and which users could think of as their "administrator" logon). Microsoft, among other leaders in the industry, recommend this method as a best practice for everybody (who needs it), whether in a domain or not, not just as a work-around.
Posted by carlsondale@...
28th Aug 2006