Restricted Groups issue



I had a question regarding Restricted Groups and how I can grant a few
individuals local administrative rights to their workstations. Unfortunately
the users are scattered throughout different OU's, so I can't apply the
Restricted Groups GPO to the top of each OU because they would be added to
the local administrators group for all PC's within that OU, not just theirs.
I already have it set up so that Domain Admins and the OIT Group are pushed
through Restricted Groups to the Local Administators Group on all PCs. I was
also thinking about a script with Net Local Group Administrators <User>
/ADD, but how would I incorporated it so that it only worked on certain
individual objects (Startup Scripts?). I was wondering if someone could help
with isolating certain (Computers or Users) to the local Administrators
Group without adding everyone else. Thank You for your time and effort, it
is greatly appreciated.

Windows XP and 2000 Clients (Approx 250)

Windows 2003 DC's (2)

Regards,

Dave Leonardi


.



Relevant Pages

  • Re: restricted groups for local admin rights
    ... Restricted Groups will not want to do what you want them. ... Whether the user is in the local administrators group on a domain computer ... then bypass domain user configuration Group Policy. ... to impossible to get the application to work as a regular user. ...
    (microsoft.public.windows.group_policy)
  • Re: I need to give an AD user the ability to install SW on PCs
    ... user logging in would have to have local Administrators access to add ... Maybe startup script would work but I ... Just slap the computers in question in comps.txt (grab your computers from ... Have you already had a look at "Restricted Groups"? ...
    (microsoft.public.windows.group_policy)
  • Re: Group Policy Problem
    ... Found it, restricted groups. ... On my workstations if I add a user to the "local administrators" group then run gpupdate /force the user I have added is removed. ...
    (microsoft.public.windows.server.active_directory)
  • Re: restricted groups for local admin rights
    ... I'm referring to local administrators and not domain administrators?) ... > describe you want to use the "member of" option for restricted groups. ... > way you can add a global group to the administrators group without affecting ...
    (microsoft.public.windows.group_policy)
  • Re: Retaining local administrator groups when using restricted groups.
    ... Restricted Groups can do this natively. ... whether or not to keep existing local admins or remove them. ... > restricted group we place on the workstations. ... > local administrators group with out using restricted groups. ...
    (microsoft.public.win2000.group_policy)

Loading