Re: Disabling Local user accounts on member servers and workstations

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi

Assuming that you're talking about of Non-DCs:
- Create an OU, move servers into it.
- Create a new GPO, and configure the restriction groups policy (Be careful
the restriction groups policy will remove all members of the group that
you're configuring):
Restricted groups policy check:

Description of Group Policy Restricted Groups

http://support.microsoft.com/Default.aspx?kbid=279301



Updates to Restricted Groups ("Member of") behavior of user-defined local
groups

http://support.microsoft.com/default.aspx?kbid=810076


--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"James" <James@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:6A59FDE4-6D15-4909-8C0E-CF89F6CA46D6@xxxxxxxxxxxxxxxx
I have a local user account that is a member of the local admins group on
over 100 hundred servers. I would like to disable this local account from
a
central location (my pc) instead of logging into each server and manually
disabling. I am a domain admin.

I would also prefer not to do this by using computer management and
connecting to the servers I want to disable the account on.

If I cannot do this i'd like to at least be able to change the password of
this local user account from my pc instead of logging into each server.
Can
this be done with a script or batch file. If so can anyone provide some
sample code as I am not very familiar with writing scripts?



.



Relevant Pages

  • Restricted Groups using local security policy
    ... We want to use restricted groups to lock down the administrators group on ... these servers using local security policy. ... Is it possible to use restricted groups via local security policies on ...
    (microsoft.public.win2000.security)
  • Re: PERFMON4 from XP to 2000, different domains...
    ... If there are a lot of servers that can be done via Group Policy ... Restricted Groups to manage groups on domain workstations implement it at ... > if I log on XP as domain2 admin I can read them without problem... ...
    (microsoft.public.win2000.security)
  • Re: server local admin group
    ... You can add the domain group to the local administrators group manually ... using lusrmgr.msc on each server or via Group Policy Restricted Groups ... "member of" if you have a large number of servers to do such to. ...
    (microsoft.public.security)
  • Re: Pop3 Connector not working.
    ... Andrew ... > Yet another problem can be a corrupted SMTP connector. ... >> Error 0x534 occurs when a user account in one or more Group Policy ... >> Restricted Groups branch of a GPO. ...
    (microsoft.public.windows.server.sbs)
  • Re: Pop3 Connector not working.
    ... Error 0x534 occurs when a user account in one or more Group Policy objects ... Restricted Groups branch of a GPO. ... > get to the Pop3 mailbox is also listed as an SMTP address for the Exchange ...
    (microsoft.public.windows.server.sbs)