• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Active directory

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

AMD Phreak

Member
Joined
Apr 2, 2003
Location
255.255.255.255
Anyone here fluent in AD? I am working on a DC that I have created for my local network and another remote network.

Right now the layout is three workstations locally here at my location, and up to 5 workstations at the remote location. The two are tied together via VPN, with the DC residing at my location. There is currently one member server here, but in the future there is one planned for the remote location.

What I want:

What I am looking for is a security policy that still allows functionality on the computer. This would include the ability to install programs, without being part of the administrator or domain admin group. I think I can figure out everything else but this component is driving me crazy. Any help? Any other suggestions that you or others know of to make the domain a bit more user friendly but still secure?
 
The ability to install programs requires the ability to modify the registry. I don't think there is a way around it. The users who need this would have to local administrators. For security, you could then make a gpo in the ad to reduce what the users can do . I may be wrong but thats my understanding of windows permissions.
 
Back