Group Policy and restricting local administrators




Greetings,

I am currently working on developing a group policy on a AD container
of servers. I certain users to have virtually local administrator
access to a series of servers, but there are a few things I do not want
them to be able to do. Namely:

1) Not be able to access User Management at all.
2) Not be able to remove entries in the event logs.

I have been successful--using the group policy editor--in limiting
users inside of a container from be able to access the User Management
and Event Viewer MMC snap-ins, but the problem is that is applies to
every system they are on (since those items are under User Settings I
gather). And ideally, I still want these users to be able to view the
event log. But I want them to apply to the systems in the
container...no matter who logs on...except the local administrator
account or of course the domain admin.

I think I am not going about this correctly and I am not terribly
familar with group policy. But I am quite certain it is possible to do
this.

Any assistance is greatly appreciated.

--Daniel

.



Relevant Pages

  • RE: Group Policy Question on firewalls
    ... The simple answer is to make a group policy object and apply it the AD ... do not want to be firewalled are in a different container and the policy ... I don't want to also turn on the firewalls on my ... Windows 2003 servers as this will likely block normal network traffic. ...
    (Focus-Microsoft)
  • Re: Terminal Server GPO Issue
    ... servers that is not in the OU where the GPO is supposed to be applied and I ... Microsoft Windows Operating System Group Policy Result tool v2.0 ... Sharepoint Auth GPO ... Event Log Settings ...
    (microsoft.public.windows.server.active_directory)
  • Re: Terminal Server GPO Issue
    ... servers that is not in the OU where the GPO is supposed to be applied and I ... Microsoft Windows Operating System Group Policy Result tool v2.0 ... Sharepoint Auth GPO ... Event Log Settings ...
    (microsoft.public.windows.server.active_directory)
  • Re: Application error log
    ... Disclaimer: This posting is provided "AS IS" with no warranties, ... I have 3 servers in our office running win 2003 R2 servers ... I did not set any group policy in my servers. ...
    (microsoft.public.windows.server.networking)
  • Re: Application error log
    ... Are the errors because of this missing entry. ... I have 3 servers in our office running win 2003 R2 servers ... I did not set any group policy in my servers. ... Windows cannot query for the list of Group Policy objects. ...
    (microsoft.public.windows.server.networking)