How to create Local Admin on Server 2022 with right privileges

Anonymous
2024-09-30T16:57:49+00:00

I want a local admin who helps in the installations and removing stuff but he should not have the access to edit the OU on windows server. How can I achieve that?

I created a local admin group with group scope as Global and group type as security and added the user in that group. what is the next step shall i do and what all changes shall I make in GPO ? also can I make sure to add all my users in group so that they dont need admin prompts to install apps ?

Windows Server Identity and access User logon and profiles

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Anonymous
    2024-10-02T02:32:04+00:00

    Hello Princeapr9,

    Thank you for posting in Microsoft Community forum.

    Do you mean this 2022 server is also a Domain Controller?

    If so, we cannot create local accounts on one DC, we cannot open local users and groups.

    All the accounts on Domain Controller you create are domain accounts.

    Based on the description "who helps in the installations and removing stuff", what do you want to the user/group to install and remove?
    Where do you want to the user/group to install and remove? Domain client machines or Domain Controllers?

    I hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    0 comments No comments
  2. Anonymous
    2024-10-02T02:43:06+00:00

    I just want to create a security group where admin should only be able to install or download software but the admin when logged on server should not be able to edit existing OU’s And only manage the ou assigned to him , this is something we can do from gpo but i dont know where to select? another thing is that i want users to download and install apps without admin prompts

    0 comments No comments
  3. Anonymous
    2024-10-04T10:52:39+00:00

    Hello

    Greetings!
    I just want to create a security group where admin should only be able to install or download softwareA: Admin can do many things than install or download software. I'm afraid it may be difficult to restrict administrators from only doing installing and uninstalling software.

    another thing is that i want users to download and install apps without admin prompts

    A: Administrator privileges are required to install and uninstall a lot of software. The normal user can only install and uninstall very little software.

    I hope the information above is helpful.

    Best Regards,
    Daisy Zhou

    0 comments No comments
  4. Anonymous
    2024-10-23T20:57:20+00:00

    I know how the security group works- my question is for example - I create a security group called "Local Admin" and gave admin permission via seperate gpo where user can install any software without admin prompts !! and all I want is my local admin whenever he access the server he should not be able to edit or make changes to existing OU but he can view it. I remember this is possible because I have seen a video before but I can't find it on youtube anymore

    0 comments No comments
  5. Anonymous
    2024-10-24T08:58:05+00:00

    Hello

    Good day!

    Do you want to create normal domain user accounts on DC and add these normal domain user accounts to one domain security group, and then add this security group to local Administrators group on domain machines via GPO?

    Best Regards,
    Daisy Zhou

    0 comments No comments