My shop is running Windows NT 4 SP6a in a single domain configuration. We have several remote locations running a single BDC at each site. My goal is to allow an admin at each of these sites to have control over software installs and light admin responsibilities without being able to make changes to servers outside of their site. I know Windows 2000 AD is the way to go but we are not there yet. Does anyone know how I can better lockdown a “local admin” account? Which persmissions should be set?
Thank you in advance for your help.
Mark