I have just started working in an organisation running windows 2003 server and various other server equipment. Anyway, the 30 or more user PC’s that are running windows 2000 or windows xp have all in their Administrators Group an Active Directory group called ‘PC_Admins’ and within that group in AD all the users across the organisation are added there. I’m fairly new to active directory and want to know why this practice is used and also the pro’s and con’s to it being used (I’ve gathered that some apps will not work without the domain user as a local admin). I guess this practice was used in a prev organisation I worked for but there each domain user was added separately to the local admin without the use of a group.
Thanks in advance for shedding the light for me.