Re: Add user/group to local group via Group Policy



In a GPO that has all machines which should be affected in its scope,
define a restricted group naming it Domain Admins.
DO NOT alter the Members list of this restricted group definition.
Change the Member Of list so that it names the built-in Administrators
group.

This will guarantee that Domain Admins is a member of Administrators
on all machines to which the GPO is applied, and it will not make any
other changes to the membership of the Administrators groups.

This is is somewhat confusingly stated in KB
http://support.microsoft.com/kb/810076


"RollNpc" <RollNpc@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AA5EC2E6-0183-4BD5-8D16-C15C31051D16@xxxxxxxxxxxxxxxx
I want to add/force my domain administrators group to all machines in my
domain via group policy without disruption of service and without changing
any current memebers.

Some of my local administrators have removed the domain administrators
accounts from the local groups and i want to put the domain admins back
in.
If i use the standard GPO it replaces memeberships, i just awant to add
the
domain admins.


--




.



Relevant Pages

  • Re: AD Design
    ... Within a new domain the domain admins can administer the complete domain, ... If you add them to the Enterprise admins, they are able to administer the complete forest. ... By default, this group is a member of the Administrators group on all domain controllers, all domain workstations, and all domain member servers at the time they are joined to the domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Opening workstation event view = Access Denied
    ... You can add domain groups (or user accounts) to local groups using Restricted Groups in a GPO. ... In a domain of any size, you might NOT want the people that administer workstations to be Domain Admins. ... You can then designate which user accounts are workstation administrators without also granting them administrative rights to the whole domain. ... being a member of the Domain Admins group does NOT necesarily mean you are an administrator on the domain member computer. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to make give cross-domain "Domain Admins" permissions
    ... that "Domain Admins" do. ... Domain Admins don't have any special permissions, ... member of administrators on every domain member and the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Opening workstation event view = Access Denied
    ... Domain Admins gets added to the local group called Administrators. ... being a member of the Domain Admins group does NOT necesarily mean you ... Remote Desktop Users pmd.local/Builtin ...
    (microsoft.public.windows.server.active_directory)
  • Re: add group back.
    ... In the new GPO, under computer, security settings, choose Restricted groups. ... Create a new entry for administrators and make Domain Admins a member. ...
    (microsoft.public.windows.server.general)

Loading