Re: Group Policy - Restricted Group



hi Meinolf,

yeah your right on the domain users, just used that :). I'll study the
links.

Thanks again

Allan


"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb661c97d8cb7074bfa19d94@xxxxxxxxxxxxxxxxxxxxxxx
Hello Allan,

Why do you make them power users, any reason? Our users are domain users,
that's all. If they need additional software for working we deploy that
with softwaredistribution policy.

See here about software distribution:
http://technet.microsoft.com/en-us/library/cc738858.aspx

http://technet.microsoft.com/en-us/library/cc778924.aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

Hi Meinolf,

Thank you for this. But can you give me specific info on this. i
think i have tried everything in GPO but I can't seem nto configure
it correctly. Here is what I'll do.

1. On local PC i'll make the AD users as Power Users.
2. In GPO set OU's (AD users resides) will have unrestricted
software
installation.
PArt 1 is easy but part 2 where exactly this resides at GPO.

Your a big help. Thanks a lot.

Allan
"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb661c9628cb706e7b3b9a34@xxxxxxxxxxxxxxxxxxxxxxx
Hello Allan,

If your users are local admin they have full control over the local
machine. Remove them from the local admin group and consider to use
GPO to install software for the domain users/machines.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Hi,

Need some help in GPO. i have a Windows 2003 Enterprise Server
running as Domain Controller. I our Active Directory users to have
this policies.

1. Local user can install any application on their local PC.
2. Set restrictions on LAN Configuration, Desktop and other
security
settings.
My current setting is each AD users are administrator on their local
PC. So restricting item 2 is quite impossible.
So how to work on this? I'm reading and browsing about Restricted
Group in GPO. Is this the answer tomy query? If it is how will I set
this up?

Hope for your assistance.

Thank you,

Allan






.



Relevant Pages

  • Re: Deploying Office
    ... you need to change your users to power users on each computer. ... users> add domain users or everyone or such to that group. ... > I deploy MS office 2k via GPO but when the user opens for example Outlook ... > ever they reopen an office app. ...
    (microsoft.public.win2000.group_policy)
  • Re: Software Restrictions
    ... >>I want to implement 2 GPOs to restrict certain software. ... >> be applied to the Domain Users security group. ... > But you CAN set it in the User section of the GPO and have it ... >> this GPO will be applied to the Project Users security group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Computer Management Security Problem
    ... Check:To view a user's group membership for a domain, use the resource kit utility Showgrps.exe.. ... Users group to the Administrators group? ... either using the Default Domain GPO or a GPO at the domain level to ... By using a GPO at the domain level and specifying that Domain Users are ...
    (microsoft.public.win2000.security)
  • Re: Deploying Office
    ... Is there a way to do that via GPO or do i need to go to every machine and do ... > you need to change your users to power users on each computer. ... > users> add domain users or everyone or such to that group. ... >> The GPO is assigned under computer configuration. ...
    (microsoft.public.win2000.group_policy)
  • Re: Apply User Settings only when using specific Computers
    ... Group Policy loopback processing mode and specified ... The computers that are to process the GPO and so see that it ... modified the membership of Domain Users). ...
    (microsoft.public.windows.group_policy)