Re: Group Policy setting for restricting creation of local user accounts



"B.E. Jorgenson" <jorgenson.b@xxxxxxxxx> wrote in message
news:1159560514.691170.269170@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Right, but I am looking for a group policy, security template, or local
security policy.


You could use a restricted group definintion in a GPO applied at an
OU level (not to DC OU or to Domain) that carries definition for
Administrators naming only what you want included in them all.
It is often convenient for that GPO to also had a rename policy set
renaming the built-in Administrator


KenB wrote:
Restricting the users to non-administrator access will prevent them from
being able to create accounts on the computers.

Ken


"B.E. Jorgenson" <jorgenson.b@xxxxxxxxx> wrote in message
news:1159380582.077768.320930@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Is there a way through group policy to restrict any user from creating
local computer user accounts when the computer is joined to the domain?
This has nothing to do with logon locally but actually creating a local
user account.

Thanks,
Brian




.