Re: changing the ACLs on the builtin objects

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance




Hello user,

To add members to the local administrators use restricted groups with a GPO, easy and effective way.
http://www.frickelsoft.net/blog/?p=13

Let not domain users decide that. If you talk about helpdesk people use delegate control on the OU where they should be able to work. see also this one about some options:
http://blogs.dirteam.com/blogs/jorge/archive/2006/01/05/369.aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Is there any way of changing the ACLs on the builtin objects? (e.g. to
grant a domain group the permission to add users to the builtin
administrators group on a workstation). (Other than SubinACL, cause
that doesn't work.)



.



Relevant Pages

  • Re: 2003 AD
    ... There is something called 'Restricted Groups' GPO that might help you. ... to certain areas of the registry or to some folder. ... > E-Backoffice require that the user be a member of the local administrators ...
    (microsoft.public.win2000.group_policy)
  • Re: Local Admin
    ... with the Out-of-the-Box configuration the use of this GPO will flush the ... the group that is your focus in the local Administrators group. ... WIN XP Pro system in my environment. ... > You can do this with the Restricted Groups function of Group Policy: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Restricted group mistake - now BSOD for USERS groups
    ... Look and see what the membership of the local users group is. ... Try adding domain users group for the domain and authenticated ... If you do use restricted groups and if it works, ... > policy and stupidly did it on a live GPO instead of my test GPO. ...
    (microsoft.public.win2000.group_policy)
  • Re: Restricted group mistake - now BSOD for USERS groups
    ... Try adding domain users group for the domain and ... >> restricted groups. ... >> policy and stupidly did it on a live GPO instead of my test GPO. ... >> logon we will now see GPO security settings and personal settings be ...
    (microsoft.public.win2000.group_policy)
  • Re: Administering OUs
    ... > eloborate please?. ... restricted groups are proper solution for this problem. ... Restricted groups are defined in the GPO (for example GPO assigned on ... of local administrators group this setting will be forced on all ...
    (microsoft.public.win2000.active_directory)