Domain Group For Installing Software
They also do not have local accounts.
Domain group for installing software. I d develop a coordinated process of installing the software with group policy and updating it by deploying new packages when patches are released. No i read that users only in the domain users group cannot install software. Managing updates for adobe reader is the same answer i d give to you re.
Under user configuration expand software settings. My plan is to remove users as local admins and give them standard user rights to workstations. I d like to lock down software installs on workstation in a domain.
I performed a gpupdate on the domain controller itself and after a reboot all of the software installed on my domain controller but not client machines. I am new to server 2012 and i am trying to figure out how to allow a non administrator the ability to install and modify software on a computer joined to the domain or domain controller. Right click software installation point to new and then click package.
For example file server share file name msi. I m using windows 10 as a client and windows server 2012 r2 for server. Click the group policy tab click the policy that you want and then click edit.
Right click the policy you just created and click edit. By default users are members of the domain users group and also an office distribution group for the everybody email address. You can t have local users groups on a domain controller so using restricted groups in gp won t work i ve tried this.
Create a folder in server and share it with appropriate permission for domain users to execute msi files. Managing updates for the jre and other necessary evil software like it. Then setup a limited rights admin account or group that can be used for installing software on workstations instead of using the domain admin s account.