Hi,
I have AD infrastructure running on 2012R2 domain controller, my client PC’s are win7, win10.
My desktop user’s needs admin access for their using desktop alone, there are 4000 desktops resides in my network.
I aware adding individual user to local administrators group does not recommended.
If I follow AGLP method for providing access, however my users will get admin access to all desktops.
How do I grant individual users access to each desktops, is there any option available in GPO.
Additionally I want to restrict my users adding other users in local administrators group of their owning desktops.