My company is in the process of moving from Novell to an AD domain. Every user was set up with full local administrator rights on their XP machines. Now when I add them to the new AD domain they are having issues unless I add each user to the local admins group. For example, the first person I tested adding to the AD domain could only open local documents as Read Only. When I added the user to the domain I copied the local profile to the domain profile. I also gave the domain user rights to the local profile. The only way everything worked smoothly was to add them to the local administrators group. I would prefer not to do that. Does anyone know how I can give users full control of their local profiles, which had full local admin rights, without having to add them to the local administrators group? Any help would be much appreciated.