Re: Need to fix Local Admin rights problem
- From: "kj" <kj@xxxxxxxxxxx>
- Date: Wed, 1 Mar 2006 16:46:58 -0700
That it will. You'd have to use Restricted groups to take out the riff-raff,
remove the policy, and then add back in the one-offs manually or with
cusrmgr.
Otherwise, "certain groups" on "certain machines" would involve multiple
instances of restricted group policy objects and appropriate OU structures
or complex GPO filtering.
--
/kj
"Lewis Howell" <lewisbhowell@xxxxxxxxx> wrote in message
news:Oo3yHZYPGHA.740@xxxxxxxxxxxxxxxxxxxxxxx
FYI: Once you setup this policy (Computer Config/Security
Settings/Restricted Groups) all members of the Local Administrators group
WILL BE overwritten. The GPO does not merge the members.
"kj" <kj@xxxxxxxxxxx> wrote in message
news:%23cW0XXVPGHA.1760@xxxxxxxxxxxxxxxxxxxxxxx
You'll probably find a combination of restricted groups and cusrmgr.exe
tools that will meet your needs.
--
/kj
"Bad Beagle" <maxwelli@xxxxxxxxxxxxxxxx> wrote in message
news:ew0IhAVPGHA.2268@xxxxxxxxxxxxxxxxxxxxxxx
I need to fix a big issue. All our users have local admin rights on
their machines. When the techs setup the machines they add domain\users
to the administrators group. Every domain user on my network can connect
to each others machines. I would like to fix this with a gpo. I cannot
remove local admin rights yet but I would at least like to take one step.
I would like to allow certain groups to local admin rights on certain
machines. I would like to do this by ou or group.
Can someone point me in the right direction?
.
- References:
- Need to fix Local Admin rights problem
- From: Bad Beagle
- Re: Need to fix Local Admin rights problem
- From: kj
- Re: Need to fix Local Admin rights problem
- From: Lewis Howell
- Need to fix Local Admin rights problem
- Prev by Date: Re: ASSIGN GPO TO GROUP OF COMPUTERS
- Next by Date: Re: Random trouble enforcing group policy
- Previous by thread: Re: Need to fix Local Admin rights problem
- Next by thread: Screen saver for presentation computers
- Index(es):
Relevant Pages
|