Question:
I have a user that I don't want to be an Admin or Domain Admin, but
which I do want to have the ability to log into Terminal Services on
our Windows Servers remotely. The most obvious thing to do is to add
the user to the "Remote Desktop Users" group locally on every server,
but I don't really want to do that manually. I'm wondering:
What's the best way to add a domain user to a local group on every
member of an OU in AD (e.g. we have a "servers" OU which contains all
of our Windows servers)?
|