Correct - just one thing, which is what started me down this whole path. If I configure Domain Users to be a member of Administrators, all domain users would have *ACROSS THE NETWORK* administrative access to the PC (\\computer\c$). This is what they don't want. Management is willing to accept that because of the physical security on the building, that anyone who can *SIT* at the PC is OK to be an Admin for that PC and that session, but they don't want anyone on the network to be able to browse any PC at other locations. Stupid, I know...but I do genuinely appreciate everyone's thoughts on this.