Re: Where is Local Admin group in GPO?



You can also use the member of function in restricted groups to add users
which do not affect the already in place users in the local admin group.

--
G Johansson
fantomen@xxxxxxxxxxxxxxx
http://GPfaq.se


"rickym61" <rickym61@xxxxxxxxxxx> skrev i meddelandet
news:F3AE4185-4AA9-4295-9D01-9531C52EFB85@xxxxxxxxxxxxxxxx
Hi Joe,

You can add a user to the local Admins group via a gpo using the
restricted
group option..

Computer Configuration\Windows Settings\Security Settings\Restricted
Groups ->Add Group->

Restricted groups are very effective, but they will remove all accounts
and
groups from the local group specified so your GPO has to accurately state
all the accounts and groups that you want in your local admin group.....

From the help topic on the item: "When a restricted Group Policy is
enforced, any current member of a restricted group that is not on the
Members list is removed. Any user on the Members list who is not currently
a
member of the restricted group is added."

Regards,

"Joe" <Joe@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:84B74350-19C8-4FA6-976A-682AB84D00A6@xxxxxxxxxxxxxxxx
I want to use a group policy with a Restricted Group to add users to the
Local Admin group on all Win XP machines. I've got a handle on the
Restricted Group (I think) but I can't find where in the GPO to specify
members of the Local Admin group. Also, how do I specify a local user
(i.e.,
local administrator) in a domain GPO?

Thanks,
Joe



.



Relevant Pages

  • Re: Desktop Admin - HELP
    ... restricted group in my GPO and refreshed my policy and all should be good... ... local admin rights... ... ALSO, i created a brand new GPO to use, and it had the same results... ...
    (microsoft.public.win2000.active_directory)
  • Group policy tatooing with restricted group ? or strange behaviour !
    ... Configuration 2 --> During three months, we have changed this GPO and the restricted group was defined witht the "member of" parameter so a user was able to add himself to the local admin group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegating Add/Remove program authority
    ... are located in an OU called OED I have set up a GPO for OED. ... with "oedbuild" as member. ... > Unless you restrict this to a specific machine this group (Blah Blah) will ... > be a local admin of all machines that apply this gpo ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegating Add/Remove program authority
    ... You could use restricted group ... not a good idea to use a gpo. ... Unless you restrict this to a specific machine this group (Blah Blah) will ... be a local admin of all machines that apply this gpo ...
    (microsoft.public.win2000.active_directory)
  • Installing software and security problem for my users...
    ... I want to deploy some application through a GPO. ... of the local admin group, so not authorized to install an application ... I' ve checked the "always install with elevated privilege" ... My users are member of the local power user group of each computer. ...
    (microsoft.public.windows.group_policy)

Loading