Group policy tatooing with restricted group ? or strange behaviour !




Hello,

we have Windows 2000/Xp clients in our Active Directory.

Configuration 1 --> We had a GPO applied on computers that defined a restricted group for BUILTIN\Administrators. (So, if a user wanted to add himself to his local administrators group,his user account was automatically removed from this group).

Configuration 2 --> During three months, we have changed this GPO and the restricted group was defined witht the "member of" parameter so a user was able to add himself to the local admin group.

Configuration 3 (= configuration 1) --> Then, as some of the users knew the local admin password and have added without autorization to the local admin group, we have configured the restricted group as before (and so users are removed from the local admin group).

now the problem ...

If a user power on his computer with the network disabled or if the GPO is not applied for any reason), the local admin group is identical to what is was during the "configuration 2" and so some users are local admin ...

Is it normal ?

Thank you

--
Eric


.



Relevant Pages

  • Re: Group policy tatooing with restricted group ? or strange behaviour !
    ... restricted group for BUILTIN\Administrators. ... Configuration 2 --> During three months, we have changed this GPO and ... user was able to add himself to the local admin group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Desktop Admin - HELP
    ... restricted group in my GPO and refreshed my policy and all should be good... ... local admin rights... ... ALSO, i created a brand new GPO to use, and it had the same results... ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegating Add/Remove program authority
    ... You could use restricted group ... not a good idea to use a gpo. ... Unless you restrict this to a specific machine this group (Blah Blah) will ... be a local admin of all machines that apply this gpo ...
    (microsoft.public.win2000.active_directory)
  • Re: Where is Local Admin group in GPO?
    ... You can also use the member of function in restricted groups to add users ... which do not affect the already in place users in the local admin group. ... You can add a user to the local Admins group via a gpo using the ... From the help topic on the item: "When a restricted Group Policy is ...
    (microsoft.public.windows.group_policy)
  • Re: Local Admin on workstation
    ... except making them local admin through restricted group in GPO, they won't be able to install software. ... You may use GPO to deploy software through GPO without making them admin. ... You may also just use psexec to make a silent install remotely.. ...
    (microsoft.public.windows.server.active_directory)

Loading