Re: Local admin accounts gone haywire
- From: Florian Frommherz <florian@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 08 Mar 2006 14:40:36 +0100
Howdy Frisk!
Frisk wrote:
After forcing a gp update this seemed to work, all techs automatically
have local admin privileges on any workstation they logged onto, but
after a little analysis, i decided this was a little unsafe and removed
the restrictive group.
Okay.
When i log on as the domain administrator on any workstation, i no
longer have local administrative rights on that machine, unless i
rejoin the workstation to the domain, and i dont really want to have to
do that with 200+ machines when i've done it already.
That's clear. See: The Restricted Groups feature doesn't _add_ the users to the admins group, it _replaces_ the users located in that group. In simple words: you replaced yourself and the local administrators of the machines by the tech-group as admins.
Also, the tech group still always have local admin privileges on
workstations (even workstations they've never logged onto before) even
though non are members of any administrator group and i removed the
restrictive groups policy.
After you removed the Restricted Group-policy, the tech-users still belong to the admins group because no one took them out. You would manually have to take them out.
Can anyone help me understand whats going on? I really dont want to
have to rebuild, and i used to feel that i understood win2000
networking pretty well but this has just stumpt me.
The easiest solution would be: add a new Restricted Groups policy and let domain-admins have administrator rights on the local machines. Don't forget to explicitly add the local admins to the administrators group. After applying the GP, the tech-users will automatically drop out...
cheers,
Florian
--
Nachwuschsadmin aus dem Süddeutschen/Germany.
eMail: Vorname [bei] frickelsoft [Punkt] net.
.
- Follow-Ups:
- Re: Local admin accounts gone haywire
- From: Frisk
- Re: Local admin accounts gone haywire
- References:
- Local admin accounts gone haywire
- From: Frisk
- Local admin accounts gone haywire
- Prev by Date: Admin Templates display in Foreign Language
- Next by Date: Re: Local admin accounts gone haywire
- Previous by thread: Local admin accounts gone haywire
- Next by thread: Re: Local admin accounts gone haywire
- Index(es):
Relevant Pages
|