Adding users to a power user group

Windows security threat expert Kevin Beaver shares helpful articles about how to add users to a local power user group.

On my Windows Server 2003 (domain controller) I allowed one user to remotely log on to the server. He can run all applications except one. How can I put him in a local power user group on DC? Is there another solution to allow him to run that specific application without putting him in the admins domain?
It sounds like you're looking for Software Restriction Policies where you can disallow everything except for certain applications you specify. This Microsoft knowledgebase article outlines what to do - just keep this issue outline by Mark Russinovich in mind.

