Can Group Policy Use Rules That Refer to Custom Local Groups?



Can group policy be used to populate each member server with rules that
include local groups that are not BUILTIN groups, but custom? For
example, we want to create a local group on each machine that builds a list
of users that are allowed to run as services (Logon as a Service right in
group policy). We want that group name to be standardized, something like
ServiceUsersGroup. The group policy would then give the Login as a
Service right to a group ServiceUsersGroup, and the contents of that group
gets administered locally since it is a local group.

The reason we wanted to do this is that we wanted to stop applications that
just automatically insert themselves into this right. We want the decision
to run as a service to be a conscious decision that we control and that
can't be done secretly. We also have some service userids that would be
defined at the domain level and would be able to run on any workstation, so
we need group policy for that as well, but we don't want to deny additional
users to be added for specific machines.

What we are finding is that if the local group doesn't exist on a particular
member server, then it appears that group policy simply kicks up a 1202
event code and stops trying to apply itself further.

Are we trying for a design here that Microsoft just didn't anticipate, or is
there a better way to accomplish the same requirements?

--
Will


.



Relevant Pages

  • Re: What the "Local Group Policy" definition?
    ... Local Group Policy is the built in Group Policy for that computer and can be ... However settings defined in local Group Policy will be ... that a change that is applied to the local server or pc by an admin user? ...
    (microsoft.public.windows.group_policy)
  • Re: Can Internet Explorer be Deleted?
    ... removing access to Internet Explorer does not affect e-mail. ... GPO for the machines that should have IE disabled. ... "gpedit.msc" to open the Group Policy MMC console. ... machines, then I recommend using AD GPOs instead of local Group Policies, ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Privilege to install / uninstall software on numerous systems.
    ... Well, you won't be able to add a domain local group to a computer local group, so that won't work! ... But in general, if you want to use "this group is a member of" then what you do is when you do the "Add Group", you would add the group you want to make a member of the Power Users Group. ... Script Group Policy Settings with the GPExpert Scripting Toolkit for PowerShell! ...
    (microsoft.public.windows.group_policy)
  • Re: GP with SUS
    ... a few minutes and just said they do not suppport SUS. ... you are using local Group ... Does any Group Policy setting apply to regular ... >> admin user or normal user with local admin rights.The ...
    (microsoft.public.win2000.group_policy)
  • RE: USERENV Even 1030 error on Member Server
    ... Enterprise-based Member Server. ... you cannot start Group Policy snap-ins. ... Please do the last windows update to the Windows 2003 Enterprise-based ... Enterprise-based Member Server has Dynamic Updates set to No. ...
    (microsoft.public.windows.server.sbs)