Re: Administrators Group in Local Users and Groups



Ok, this is good. I set up the gpo for the domain admins and my new
helpdesk group.
It works great for adding or deleting users from those groups.

But I still have no idea how to propagate that info down to the workstation.
I assume I need to make these new restricted groups a member of the local
administrators group, but it won't let me browse outside the active
directory and putting in administrators just goes to the domain one.
The first link you sent starts talking about adding them to the local
security accounts, but doesn't say how. It just shows another domain group
added in.

I know I'm probably missing something simple, but isn't that always the way?

Please help

Thanks
Mark

"Paul Bergson" <pbergson@xxxxxxxxxx> wrote in message
news:%23wKk76$CGHA.2040@xxxxxxxxxxxxxxxxxxxxxxx
> You could use the restricted user group gpo setting
> http://www.windowsecurity.com/articles/Using-Restricted-Groups.html
>
>
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechRef/156780ef-eb36-4433-b3fe-1b1a15c18f6a.mspx
>
>
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_scerestrictgroups.mspx
>
>
>
> --
>
>
> Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
>
> "Mark Morrell" <morrellm@xxxxxxxx> wrote in message
> news:O204Pp%23CGHA.3684@xxxxxxxxxxxxxxxxxxxxxxx
> > Hi!
> > I am trying to find out how to add in the domain group Account Operators
> > to
> > each workstations administrator group (without going to each computer).
> >
> > Domain Admins is added into each computer when it joins the domain.
> > I want Account Operators to do the same.
> >
> > Running Server 2000 and 2003 native
> > With Workstations 2000 and XP
> > All updates as of yesterday.
> >
> > Thanks
> > Mark
> >
> >
>
>


.



Relevant Pages

  • Do Not Execute Group Policy for Admins Group
    ... so that the group policy will only apply to a certain group of users ... domain admins that logon to a computer in that OU). ... In this case the GPO would not ... it's intent is to change the user settings ...
    (microsoft.public.win2000.group_policy)
  • Re: loopback processing mode
    ... Deny Apply Policy for Domain Admins for the particular GPO Object. ...
    (microsoft.public.windows.group_policy)
  • RE: Filtering GPO
    ... When filtering the security group for the Domain Admins, ... Apply Group Policy is all that is required to ensure this GPO does not apply ...
    (microsoft.public.windows.group_policy)
  • Re: restricted groups have broken Admin access....help!
    ... With the default use of Restricted Groups GPO all of the current user ... account objects and group objects are removed from the 'focus' local group ... Domain Admins as members of their local Administrators group. ... > As soon as I set it up it stopped all my domain admin access and IUSR ...
    (microsoft.public.win2000.group_policy)