I have been researching the Net for a solution to my problem. We have a Win 2k3 Ent. R2 Server enviroment w/ XP Pro clients. We need to alter our Departmental practices regarding support duties & tasks.
Here’s the question: We want to create a seperate ‘Junior Domain Admin’ that will allow Tier 1 through Tier 3 support to accomplish the following at the local workstation level without using Domain Admin account:
Add/Remove Software
Change User Profile Level
Change Networking (IP) Information
Attach & Detach from Domain
What is the recommended route for doing this? GPO on the Domain? What would the proper Security Groups to assign this acocunt be to accomplish these tasks? Would it be setting the Domain Admin Group and then tightening the rights down under GPO? Would this be done under Computer Config or User Config? GPO is kinda uncharted for me to this degree.
We want this secondary account used rather than the Domain Admin and we wish to follow principle of least priviledge for granting the needed ‘rights’ level.
I have looked all over and there’s not much except to deter hackers or disable the built in Admin account and create a second, less known one. We don’t want ALL the powers of Domain Admin has, just a handful of rights to get local workstation tasks completed.
Is the only option to use the Local Admin account on the clients?
You help and thoughts would be greatly appreciated!
Thanks!
John in Phoenix, AZ