Correctly configure admin rights on Windows networks

Learn how to determine if your users have only the Windows admin rights that they need with this expert advice from Wes Noonan.

I have a Windows 2003 domain controller with about 200 ordinary users. Among them, ten users should have some privileges, like network configure, printer configure, software install, etc. Those ten users should not have administrative privileges, but they do. How can I control each user's admin rights on my Windows network?
Without being able to directly observe your environment, my best guess is that in order to have those admin rights, those users were made members of a group that grants them administrative privileges such as the Domain Admins group or the local Administrators group. I would review the groups that each user is a member of (right click on the user and select the "Member Of" tab), and remove any memberships that are not necessary.
This was first published in August 2007

Dig Deeper on User passwords and network permissions



Find more PRO+ content and other member only offers, here.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.



Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: