I got lot's of queries from system administrators & tech support
engineer's ,like how to allow domain user's to install software or
make any configuration changes on the client's without prompting
for password. & How to make a user group to allow performing
system changes on client's but they should not be able to perform
any changes on domain controller & Server Computer's.
So here I am sharing this article with you so you can solve this
issue:-
So Let's Start:
We are going to Complete this demand using GPO & I am using
Windows Server 2K8 R2
First go to Group Policy Management
Navigate to
Forest>YourDomain>Group Policy Objects
Right click Group Policy Objects & select New , now type
any name to your policy & press OK (in this case I am naming it
Local administrators)
Now right click policy & select edit & it will open Group Policy
Management editor.
now navigate to
Computer Configuration>Policies>Windows Settings>Security
Settings>Restricted Groups
Right click Restricted Groups & click Add group
Management editor.
now navigate to
Computer Configuration>Policies>Windows Settings>Security
Settings>Restricted Groups
Right click Restricted Groups & click Add group