Re: Group Policy



Hello Kerry,

Restricted groups work fine:
http://www.frickelsoft.net/blog/?p=13

You have to keep attention of "Members of this group" and "This group is a member of". One replaces the member, the other one adds.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


We have a requirement where certain group needs to be added into
administrators group of all computers in the domain. Tried using the
restricted groups, however this GP setting will remove all the users
and groups which are pre-exisiting in the local Administrators group
on all computers. This can be really fatal, as we might have special
business application requirements where there will be some domain or
local users/groups that have been already added to the local
administrators group, which will be removed by setting this policy. If
we decide to identify the list of users/groups that are present today
in the administrators group on computers and include that in the
restricted GP, it will give admin previlges for everyone in that group
which is not the objective.

I want to achieve the below:
The Domain User of the PC to be only added to his local administrators
group, along with another Domain Group. Can this be done?? We are
using Windows Server 2003?
Regards



.



Relevant Pages

  • Re: restricted groups for local admin rights
    ... I'm referring to local administrators and not domain administrators?) ... > describe you want to use the "member of" option for restricted groups. ... > way you can add a global group to the administrators group without affecting ...
    (microsoft.public.windows.group_policy)
  • Re: How to start cmd.exe BOTH as administrator locally AND domain admin?
    ... What you need to do, in order to get domain and local administrator access is to create a domain account that is a member of the Domain Administrators group, and then make that account also a member of the local Administrators group on the machine you're working on. ...
    (microsoft.public.windows.vista.security)
  • Re: Automatically assign user as administrator
    ... You can add a users domain account to the local administrators group on any member ... users currently in the local administrators group on those computers will be removed. ...
    (microsoft.public.win2000.security)
  • Re: How to start cmd.exe BOTH as administrator locally AND domain admin?
    ... What you need to do, in order to get domain and local administrator access is to create a domain account that is a member of the Domain Administrators group, and then make that account also a member of the local Administrators group on the machine you're working on. ... e.g. if I am domain admin and type NET STOP SPOOLER as domain admin, you get Access denied on the local Vista system. ...
    (microsoft.public.windows.vista.security)
  • Re: Local admin group
    ... Use the Restricted Groups Group Policy feature. ... How to Configure a Global Group to Be a Member of the Administrators Group ... on all Workstations: ...
    (microsoft.public.windows.server.setup)

Quantcast