Re: Smart user removing domain admin group from local admin group

From: Chriss3 (noSpamHere_at_chrisse.se)
Date: 06/30/04


Date: Wed, 30 Jun 2004 23:11:50 +0200

Good point, Also note the Restricted Group Policy will clear every existing
member to the local group and replace it with the members listed in the
policy.

-- 
Regards
Christoffer Andersson
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"ptwilliams" <ptw2001@hotmail.com> skrev i meddelandet
news:uoOOVpiXEHA.3716@TK2MSFTNGP10.phx.gbl...
> I have to chip in here.  Chris' solution is the solution to take, however,
> GPO processing does occur every 90 mins by default, but once it has
applied
> will not apply again unless the GPO is changed.  Therefore, if the users
> change the group membership after GPO application, it will not get changed
> again until foreground processing occurs - a logon (or reboot) or secedit
> /refreshpolicy machine_policy /enforce (unless you've set the security
> client side extension to process every time regardless of change).
>
> -- 
>
> Paul Williams
> _________________________________________
>  http://www.msresource.net
>
>
> Join us in our new forums!
>   http://forums.msresource.net
> _________________________________________
> "Chriss3" <noSpamHere@chrisse.se> wrote in message
> news:%23kGicnhXEHA.1128@TK2MSFTNGP10.phx.gbl...
> Hello Jody.
>
> You may not should give them local administrator rights if they not are
> trusted, the article below shows how you can link the domain admins group
to
> the local admin group, the membership will refresh every time the GPO is
> re-applied I think, it's every 90min by default.
>
> Restricted groups with in a Group Policy allow to map membership
> http://www.chrisse.se/MAQB.asp?ID=29
> -- 
> Regards
> Christoffer Andersson
>
> No email replies please - reply in the newsgroup
> ------------------------------------------------
> http://www.chrisse.se - Active Directory Tips
>
> "Jody Riding" <jriding@fishnetsecurity.com> skrev i meddelandet
> news:2314901c45e01$e21742d0$a501280a@phx.gbl...
> > I have a couple of "smart" users that are removing the
> > Domain administrator group from the local admin group on
> > their pc. This is creating serious issues with trying to
> > administrate the environment. I remember from an old job I
> > had where there was a script that was put into Active
> > Directory that would force / readd the domain admin group
> > to the local admin group. The script would force this do to
> > the fact of connection and login to AD. This force was not
> > account linked but forced do to being in the login script
> > section of AD. If anyone has any ideas on this it would be
> > greatly appriciated.
> >
> > Please feel free to email me as well.
> >
> > J Riding
>
>
>


Relevant Pages

  • Re: Add Domain Account to Local Admin Group
    ... we ran into alot of problems with it, and abandon it due to problems ... groups automatically to the local admin group on our desktops. ... groups via group policy without overriding the current members of the local ...
    (microsoft.public.win2000.advanced_server)
  • Script works / but fails on startup
    ... then add the admin group for that OU to the local admin group on the ... Administrators group is " & strAdminGroup ... 'Check if the user is already a member of the local admin group ...
    (microsoft.public.scripting.vbscript)
  • Scheduled Task will not run on Win2K3 Server (Ent Edition)
    ... control on the folders where the application is stored. ... The local admin group also has full control on the ... Registry key that the application created to store ...
    (microsoft.public.windows.server.general)
  • Re: Lost Internet access after added in admin group
    ... Are running ISA Firewall Client on the computer? ... you ping websites when you move the user to Local Admin Group? ... I added a domain user to the admin group of a local PC ... > domain user to the local admin group I lose Internet access. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Help with local adming rights on workstations
    ... >> to explicitly and individually add select users to the local machine ... >> to the local admin group on the machines, but using RG will erase any ... >> manual additions to the local admin group. ...
    (microsoft.public.win2000.group_policy)