Re: restricted groups for local admin rights



Steven,
If I want to add one domain user to one computers local administrators
group, is this the same process I would use or can I just add that domain
user to the local administrators group on that computer. When you add the
domain user to the local administrators group the message says :
administrators have complete and unrestricted access to the computer/domain.
Does this mean the user is now a domain administrator also?
Thanks again,
Sher

"Steven L Umbach" wrote:

> First off be sure to use Restricted Groups at the Organizational Unit level
> and NOT at the domain level or you run the risk of adding users to the
> administrators group for the domain. Then when you configure it at the OU
> level the computer accounts that you want these users to be local
> administrators on must be in the OU [or child OU] where you have the Group
> Policy linked to. You will not be able to browse to a local administrators
> group. Simply type in administrators as the group name. From what you
> describe you want to use the "member of" option for restricted groups. That
> way you can add a global group to the administrators group without affecting
> the current membership of the local administrators group on the computers
> you want to enforce Restricted Groups assuming that you do not want to
> strictly enforce membership of the local administrators group. I am not sure
> what icon lock means offhand. When testing your Restricted Groups be sure
> to reboot or use gpupdate to refresh computer configuration on your XP
> computers as it can otherwise take up to two hours for changes in Group
> Policy to propagate to domain computers. Hope some of this helps. --- Steve
>
>
> "Sher" <Sher@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:6B6CC986-FCD7-4527-B625-F8AD24247106@xxxxxxxxxxxxxxxx
> > Hi all,
> > 2003 server using gp for windows xp workstations
> > My goal is to use restricted groups under gp to add several users to the
> > local workstation administrator group.
> > I have read several articles on how to do it but it is confusing to me.
> > My questions:
> > can I use my current custom gp and just add the restricted group there or
> > will it override the other restrictions in the gp for the users that I add
> > to
> > the restricted group?
> > Can you give me the steps to set this up. (when I tried the other
> > articles
> > steps I couldn't browse to the local administrators group to add it as the
> > restriction point. In other words, I don't know how to tell the
> > restricted
> > group to be related to the local admins group)
> > Also, under restricted gp the icon has a lock picture on it. What does
> > this
> > mean?
> > Sorry, the restricted groups process hasn't clicked for me yet? I know I
> > could use this for other things also but just can't seem to understand the
> > process.
> > Thanks in advance for any help,
> > Sher
> >
> >
>
>
>
.



Relevant Pages

  • Re: Add another domain user group to local administrators of all computers in an OU with removing ot
    ... But if you only work with groups in restricted groups, you can just add/remove user to the group in AD you specified. ... admins group. ... Create the gpo in the ou where the Computers reside, ... "Add another domain user or group to local administrators of all ...
    (microsoft.public.windows.server.active_directory)
  • Re: restricted groups for local admin rights
    ... Restricted Groups will not want to do what you want them. ... Whether the user is in the local administrators group on a domain computer ... then bypass domain user configuration Group Policy. ... to impossible to get the application to work as a regular user. ...
    (microsoft.public.windows.group_policy)
  • Re: Group Manipulation
    ... option for your new global group that contains the users that you want to be ... The computers that you want this to be enforced on ... Restricted Groups is configured. ... >> users being local administrators on all those computers keeping in mind ...
    (microsoft.public.windows.group_policy)
  • Re: add domain account to local administrator group
    ... You can use Restricted Groups by either replacing current membership of the ... risk of adding that user/group to the administrators group for the domain. ... localgroup" command to add a user/group to the local administrators group to ...
    (microsoft.public.win2000.group_policy)
  • Re: Two XP Pro problems
    ... membership of the local groups. ... > and both computers are members of the domain. ... > One of the computers clears the Local Administrators group of all accounts ... > Kjartan Þór Kjartansson ...
    (microsoft.public.windowsxp.security_admin)