Restricted Groups - Local Users Group



I have used restricted groups in GP to control membership of both the local
users and administrators groups. I added the "domain users" group to
"Users" and "Domain Admins" group to "Administrators". The main reason I
did this was that I wanted all domain users to be restricted from making
system-wide changes to their local pc. The policy worked as I could see
that their local groups reflected my settings at the domain. The problem is
that although domain users are in the "users" group they are still able to
make system-wide changes. I tested this, as a user I can make myself a
local admin, delete system files...etc...

In the past I never used group policy for this. I would simply open control
panel, users, and add the user to the "restricted users" group. This always
worked well, and prevented them from making any critical changes to the
system. My understanding was that the "users" in computer management was
the same as the "restricted users" group shown in control panel\users. What
am I doing wrong?? I want all my domain users to be restricted through group
policy!!

HELP!


.



Relevant Pages

  • Re: \domainname.comSYSVOL is not browseable
    ... > Administrators> Full Control ... > I went to add domain users to the security settings and I ... Authenticated Users Group Has Too Many Permissions to the SYSVOL Network ...
    (microsoft.public.windows.server.dns)
  • Re: help with roaming issue
    ... Under your Security permissions, you are going to need to add Domain Users with Read/Write acces. ... Domain Admins - Full Control ... In the user profile under users properties, i have filled the profile path ...
    (microsoft.public.windows.server.sbs)
  • Re: Admin cant delete a folder
    ... Full Control and this solved 2 problems. ... and we can delete folders in folder view. ... The idea to give Domain Users full control came from this: ... >specify the newsgroup for the newsgroups search) and I ...
    (microsoft.public.sharepoint.teamservices)
  • Re: Deny access to certain IP address
    ... The reason since you want to know is that we have non domain users working in ... our offices that work for another company we have no control over that's the ... real world reason. ... > You can use IPSec rules to block access per IP address. ...
    (microsoft.public.security)
  • Re: Software Restrictions
    ... When I denied Project Users Read & Apply Policy, ... user could not access any of the restricted applications to include Project. ... >>I want to implement 2 GPOs to restrict certain software. ... >> be applied to the Domain Users security group. ...
    (microsoft.public.windows.server.active_directory)

Loading