give AD user account local admin access to all machines

Red Squirrel

No Lifer
May 24, 2003
71,100
13,992
126
www.anyf.ca
I have an AD account that is used to run a script that requires local admin access upon logon. I use an utility called CPAU to do this and that part works. This account is part of domain admins, which have local admin access to all machines, but I dont really want to have this account being a domain admin. Is there a different way of giving it local admin access to all machines without giving it domain admin rights?

I realize this is done at the PC level, and when you join a machine to a domain, the local admin group has domain admins added to it as a member. I could also manually add this particular user as a member. So can this be done to each PC through a GPO perhaps?
 

Brazen

Diamond Member
Jul 14, 2000
4,259
0
0
There is a group policy for what groups have local admin access. Make a new group for the account and add that group to the policy. I don't remember where the policy is; there was another thread on this exact same thing just last week.