Ask the Expert

Adding users to a power user group

On my Windows Server 2003 (domain controller) I allowed one user to remotely log on to the server. He can run all applications except one. How can I put him in a local power user group on DC? Is there another solution to allow him to run that specific application without putting him in the admins domain?
It sounds like you're looking for Software Restriction Policies where you can disallow everything except for certain applications you specify. This Microsoft knowledgebase article outlines what to do - just keep this issue outline by Mark Russinovich in mind.

View questions and answers from all of our Windows security experts here.

This was first published in March 2006

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.