Re: Restricted Groups????

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



We have used this policy to pretty good effect. Basically, the groups that
you specify in this policy get added to the Local Administrator Group on all
workstations the GPO applies to. The other thing to remember is that any
group NOT specified in this policy, that is already part of the Local
Administrator Group, will get removed (for instance..if you don't specify
Domain Admins...this group will get removed).

One of our Administrators applied this policy..and it had some very
interesting effects. Unfortunately, we are currently running in Mixed Mode,
so don't have the ability to use GPO's. This policy was applied, the Domain
Admins group was not specified, and so the Domain Admins was removed from all
Workstations.....and Servers....so you can imagine what that was like.

The Restricted Groups for us is set as follows:

Domain Admins
Domain\Administrator
Domain\Tech Group (this is the group we wanted added to all workstations.
Give Helpdesk local admin rights on all workstations).

What I would suggest is if you can use OU's...create a test OU, move a test
computer account to that OU, and then create a GPO using Restricted Groups
for that test area only. Then you can play around with the memberships until
you get it to do what you want.


"Cary Shultz [A.D. MVP]" wrote:

> Henry,
>
> You should be able to do it from either OS.....
>
> --
> Cary W. Shultz
> Roanoke, VA 24012
> Microsoft Active Directory MVP
>
> http://www.activedirectory-win2000.com
> http://www.grouppolicy-win2000.com
>
>
>
> "Henry Villegas" <HenryVillegas@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:5543E69F-9F45-40B2-A5B6-220ABB31A769@xxxxxxxxxxxxxxxx
> > The "Admin" workstation that I am using is XP Pro. I have a mix of 2000
> > Pro
> > and XP Pro on the network. Is this going to matter? Do I need to be
> > making
> > this GPO from a 2000 Pro Admin workstation?
> >
> > "Cary Shultz [A.D. MVP]" wrote:
> >
> >> Did you follow the MSKB Article that explains how to do this? The big
> >> thing
> >> is that you should be doing this on an "Admim" workstation. You can not
> >> really do this on a Domain Controller....
> >>
> >> --
> >> Cary W. Shultz
> >> Roanoke, VA 24012
> >> Microsoft Active Directory MVP
> >>
> >> http://www.activedirectory-win2000.com
> >> http://www.grouppolicy-win2000.com
> >>
> >>
> >>
> >> "Henry Villegas" <HenryVillegas@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
> >> message
> >> news:E1A1A057-F80A-46EA-9463-463C1411E3E7@xxxxxxxxxxxxxxxx
> >> >I am very confused with this policy. I am trying to grant a group, OU
> >> >or
> >> > user local Adminstrator rights to all computers in my domain without
> >> > giving
> >> > them Domain Admin Rights. I was able to create this policy but it
> >> > either
> >> > gave the user Domain Admin Rights or did not work at all. Please
> >> > Help!!
> >>
> >>
> >>
>
>
>
.



Relevant Pages

  • Re: Re: Server 2003 with XP/2000 users
    ... > questions i had and didnt know how to ask. ... A simple domain wide policy just to block the use of files ... > I then opened GPMC. ... removing users from Being Admins is a great Idea but could also ...
    (microsoft.public.win2000.group_policy)
  • Re: [Full-Disclosure] Blocking Music Sharing.
    ... > warrant being prohibited in an org's Acceptable Use Policy then there ... and they do need a way to try and frce compliance too. ... a shame things are this way, but, that is the way of a 'free world' ... What sort of admins ...
    (Full-Disclosure)
  • Re: XPPro : Restrict the programs a user can run
    ... creating additional "Disallow" rules for those specific programs. ... by the restriction policy from adding or replacing the files ... > I find Software Restriction Policies a great idea, ... you cannot specify this policy for only certain users,>>but for a non-domain machine, the Admin/non-Admin breakdown may be ...
    (microsoft.public.windowsxp.security_admin)
  • Re: administrator locked out of SBS 2003
    ... The Domain Admins group was a member of the Remote Operators ... My suspicion is that the policy change 'tattooed' the ... Select "All users except local administrators" ... That allowed the installation of VMware server to complete. ...
    (microsoft.public.windows.server.sbs)
  • Re: update OAB fail
    ... Yes its in the default address policy. ... MVP - Exchange ... Is this clear,don't know wat i can specify more? ... When i update my OAB for the users who working in exchange cached mode then i have no problems. ...
    (microsoft.public.exchange.setup)