Re: Local security group



Hi Mark,

Well, I do not know what means
domain account a member of the local restricted user account
but if that is some group in which their account is made member
then that also could be guaranteed through use of restricted groups

What I outlined should work for you with the environment you
have now described. Since I do not know what being a member
of the local restircted user account is meaning, I will assume it is
a group that is defined on each client machine, not a domain group.
In a new GPO linked to the OU that contains the XP client machines
Set the name of the XP built-in adm account, say to Turkey
Define three restricted groups
name Administrators
use members list to state Turkey and Domain Admins
name Domain Users
use the members-of list to state Users
leave the members list alone/empty
name "restricted users group"
uses members list to state Domain Users
Make sure that the Computer part of this new GPO is
enabled and then after it has applied each XP client
should have
1. Administrators group containing only Turkey and Domain Admins
2. Users group containing at least Domain Users
3. "local restricted group" containing only Domain Users

"Mark Bowles" <MarkBowles@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D37A6677-2F5A-4E2F-AE60-31EB71209770@xxxxxxxxxxxxxxxx
Roger,

The environment is SBS2K3(sp1) with XP workstations (sp2). We have users
that have their domain userid's as a member of the local administrators
group
on their workstation. If I remove them from the local administrators group
and have their domain account as domain user when they login using their
domain account what rights will they have? The other option is to use a
group
policy to make their domain account a member of the local restricted user
account. That setting we have tested and know that it gives the users
enough
rights to run their programs.

I have tested using a Restricted Group definition in a GPO linked to OU
containing the client machines but its not working and I am sure its
because
I don't have it setup correctly.

Thanks for any help you can offer.

Mark
"Roger Abell [MVP]" wrote:

Well, this sort of depends on just what environment you
have and what you mean by changing them all to the
restricted local security rights.
If you have a domain, then using a Restricted Group
definition in a GPO linked to OU containing the client
machines
In this GPO
1. use the policy to rename Administrator, such as to Donkey
2. define Administrators as a Restricted Group that has
as its members Domain Admins, and Donkey
Then, no domain or machine local accounts would be
members of Administrators on machines in that OU once
the GPO applied.
Now, I assume that they are all already members of Users
on those machines so that this would them leave them as
limited users (i.e. members of at most Users group)

Roger
"Mark Bowles" <MarkBowles@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:A85FDACD-52CA-41BF-A608-2E8FC62201B9@xxxxxxxxxxxxxxxx
I have a client we have been testing restricted user local rights with
all
of
there apps and it went well. I would like to use a group policy to
change
all
the workstations and their respective users to the restricted local
security
group. Can I do this using a group policy?

Thanks





.



Relevant Pages

  • Re: Rid AD of Circular Group Membership
    ... I'll try to keep this going; because it might be useful to another admin ... The quess is each has an account and uses it, ... part of stations) into the machine local Administrators group. ... Administrators Group has a members: ...
    (microsoft.public.windows.group_policy)
  • Re: Help needed setting up roaming administrator
    ... >Administrators group (just type in Administrators, don't browse for it, ... >add your Roaming Local Admins group to the Members of this group section ... GPO associated with the OU that contains the computers I want to use ... restricted group and to define the groups the restricted group will ...
    (microsoft.public.win2000.security)
  • Re: Domain Users to have Local Admin rights
    ... members inside the Restricted Group, but it still doesn't wanna work. ... all machines that are with scope of the GPO carrying the Restricted ... their local Administrators group. ... group you define a Restricted Group definition, ...
    (microsoft.public.windows.server.security)
  • Re: Security Template question
    ... all of which are members of the administrators group. ... and letting them know that this is the account for day-to-day use. ... Roger Abell ...
    (microsoft.public.win2000.security)
  • Re: Security Template question
    ... all of which are members of the administrators group. ... > account, which is to be used only when its powers are being used. ... > Roger Abell ...
    (microsoft.public.win2000.security)