/build/static/layout/Breadcrumb_cap_w.png

Make domain users/groups members of local groups

Hello

I have a need to add a domain account to the local admin group and
also grant it 'Log on as a service' right.

I have a VBScript to add the account to the admin group and a batch
file that uses the Res Kit util NTRIGHTS.EXE to agrant the 'Log on as
a service' right.

The problem I have is getting the things to execute. My apps have to
be deployed via GPOs so there is no domain access granted during the
MSI install.

If I set these as RunOnce values or as ActiveSetup values in the
registry they will only run if the user logging in has the necessary
rights.

How can I get these rights granted without leaving a trail of
sensitive passwords around?

Thanks,
lurchajn

PS: I know I can do this via GPO settings but I'd rather have a 'one-
stop-shop' approach to save the customer support monkeys from
conscious thought and the potential trauma that entails.

0 Comments   [ + ] Show comments

Answers (1)

Posted by: KPrinz 17 years ago
Fourth Degree Green Belt
0
You deploy via GPO, so you use MSIs, right?
How about adding a custom action that runs the needed actions? Then you can put the sources needed inside the msi.
Rating comments in this legacy AppDeploy message board thread won't reorder them,
so that the conversation will remain readable.
 
This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ