Retaining local administrator groups when using restricted groups.



This kinda defeats the purpose of restricted groups but my company is
currently redesigning their group policy infrastructure and have decided to
used restricted groups.

Currently their are quite a few users who are members of the local
administrators group of their assigned workstation because of business
requirements.

Goal:
To implement the use of restricted groups while allowing the current local
administrators of a system to remain local administrators.

We have thought of a few work arounds but here are some of the problems we
are facing:
1. Gather all of the members that will need local administrator rights on
their workstations to a domain local group and adding that group to the
restricted group we place on the workstations.

The problem with this is we dont want to grant all users in this group local
admin rights to all of the computers.

2. Use computer login scripts to add the specfied domain groups to the local
administrators group with out using restricted groups.

The problem with this is their is no group policy refresh, and these groups
(if a local administrator removes them) will only apply at computer logon.

Is their any known "happy medium" for meeting this requirement?


.



Relevant Pages

  • Re: Preventing Users from removing their PC from the Domain
    ... Steven L Umbach wrote: ... purpose and understand that Restricted Groups can remove all existing ... simply be removing the Restricted Group, Group Policy setting. ... you are logged on as a local administrator. ...
    (microsoft.public.win2000.security)
  • Re: Adding Local Administrators Using Group Policy
    ... Until you remove the GPO settings, any non restricted group members will be ... I created the administrator group in 'Restricted Groups' ... pushed the Domain Admin group as an local administrator, ...
    (microsoft.public.windows.group_policy)
  • Re: how to assign specific user to the local admin group when computerjointo the domain
    ... If you add a myadmingroup (create in Active directory) and the local administrator, ... For this you can use the Restricted groups feature form Active ...
    (microsoft.public.windows.server.general)
  • Re: Domain users need access to local computer files
    ... You may use restricted groups in GPO to make them members of local administrators group. ... How do I automate that a group of domain users should get local administrator rights...? ...
    (microsoft.public.windows.server.general)
  • RE: Please Help With Using Restricted Groups
    ... I tried one of your suggestions, of adding the DNS suffix. ... a GPO for the OU I am targeting for the restricted groups. ... An additional step I took was to make the group policy users and computers ... > check the DNS settings on the machine and ensure its DNS suffix and DNS ...
    (microsoft.public.win2000.active_directory)