Re: Blocking a group of users from logging onto a wkstn.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Cary Shultz [A.D. MVP] (cwshultz_at_mvps.org)
Date: 04/07/04


Date: Wed, 7 Apr 2004 08:02:01 -0400

Herb,

Do it all the time. There is a MSKB Article that shows you how to do this
for the 'local administrators' group but I do it for Power Users. The trick
is that you have to do the first three parts ( according to the MSKB
Article ) on the DC itself and then do the rest from a WIN2000 Pro system
that has the ADMINPAK installed. You have to use the WIN2000 Pro system as
the reference point. In fact, I just did it two days ago for Power
Users.....

Here is the link:

http://support.microsoft.com/?id=320065

Just remember that you are not restricted to the local Administrators
group...

Herb, no worries. I did not see any 'arguing' at all. We all have our
experiences and perspectives. I might do things one way while you might do
things another way. And Thank God for that! We share our ways and ideas
and maybe we come up with yet a better way! or some tiny improvements on
the way I or you do it! Totally agree about sharing ideas and experiences.
Lord only knows how much I miss!

HTH,

Cary

"Herb Martin" <news@LearnQuick.com> wrote in message
news:ufOPRBEHEHA.3032@TK2MSFTNGP09.phx.gbl...
> > Anyway, you could use Restricted Groups via GPO or you could manually do
> it
> > as you suggested...
>
> I like this idea -- I even teach it but no one has yet been able to
> give precise instructions on how it would be accomplished
> (especially with the GUI.)
>
> Has anyone ever tried to actually USE "restricted groups" from
> the domain GPO to specify the membership of a MACHINE
> local group?
>
> I tried and I cannot figure out how to do it. The problem is
> that the "machine local" groups don't show up on the domain
> controller GPO editor when you try to specify the group.
>
> (BTW, I teach about restricted groups too -- I just never
> promise they will work from domain to local machine groups.)
>
> Oh, another thing: I am NOT arguing with YOU (Cary), it just
> seemed like a good place to get some of you smart people to
> figure out a way if I missed it.....<grin>
>
>
> --
> Herb Martin
>
>



Relevant Pages

  • Re: Blocking a group of users from logging onto a wkstn.
    ... There is a MSKB Article that shows you how to do this ... > Just remember that you are not restricted to the local Administrators ... > "Herb Martin" wrote in message ... >> the domain GPO to specify the membership of a MACHINE ...
    (microsoft.public.win2000.active_directory)
  • Re: Adding Local Admin Accounts Using GPOs
    ... account to be used exclusively on the server, ... to remove all users from being local administrators on their machines. ... Notepad, pasted the text for the script, and saved it as AddUser.vbs (see ... I created a test OU and created the GPO policy where: ...
    (microsoft.public.windows.server.sbs)
  • Re: Allow domain user to change local permissions on domain computers, without have full right on do
    ... Create and link a GPO to the OU that contains the computer accounts for the ... key the name of the Domain Group you want added to the local Administrators ... Since, by default, Domain Controllers are in an OU that does not contain ...
    (microsoft.public.win2000.group_policy)
  • Re: 2003 AD
    ... There is something called 'Restricted Groups' GPO that might help you. ... to certain areas of the registry or to some folder. ... > E-Backoffice require that the user be a member of the local administrators ...
    (microsoft.public.win2000.group_policy)
  • Re: Local Admin
    ... with the Out-of-the-Box configuration the use of this GPO will flush the ... the group that is your focus in the local Administrators group. ... WIN XP Pro system in my environment. ... > You can do this with the Restricted Groups function of Group Policy: ...
    (microsoft.public.windows.server.active_directory)