Re: [Samba] Samba PDC + LDAP: adding user to local admin group

2008-10-10 Thread Charles Marcus
On 10/9/2008, Tim Bates ([EMAIL PROTECTED]) wrote: > If you set it at a domain level like you said, it would give them > admin rights anywhere they can log into. But if you control which workstations they can log into, this isn't really a problem - save the part of them having local admin rights..

Re: [Samba] Samba PDC + LDAP: adding user to local admin group

2008-10-10 Thread Gustavo Michels
Hi all, On Thu, Oct 9, 2008 at 6:29 PM, Tim Bates <[EMAIL PROTECTED]> wrote: > Not sure if you can do it like that, but if you only want to give them > local admin on their own computer (and not everyone else's), you're going to > want to do it on each computer manually anyway... Or via a script

RE: [Samba] Samba PDC + LDAP: adding user to local admin group

2008-10-10 Thread L.P.H. van Belle
hmmm giving users local admin rights, thats not the way to do it. and makes your network insecure.. Better control this through de domain groups. this is how i do it. i create a domain groep, add the users in it, and through loginscript i create a local group and add the domain group in it. now

Re: [Samba] Samba PDC + LDAP: adding user to local admin group

2008-10-09 Thread Tim Bates
Gustavo Michels wrote: So, what is wrong in here? Or it isn't possible to do it in the domain level? Not sure if you can do it like that, but if you only want to give them local admin on their own computer (and not everyone else's), you're going to want to do it on each computer manually anyway