Results 1 to 3 of 3

Thread: GPO to enforce Restricted Group Access

  1. #1
    jmesidor is offline 10+ Helpful Posts Happy to be helping others
    Join Date
    Dec 1969
    Posts
    10

    Default

    I want to create a GPO to enforce group access. In my environment, some users are allowed to be Local Admins on their machines so they can install software. Because my domain has been migrated to an Enterprise level where I can only manage my Department OU; when I add a machine to the domain, my dept. OU admins don't get added to the Local Admins group on the box. I use a Restricted group GPO to enforce the inclusion, but it removes everyone that was already a member except for administrator.

    Does anyone know how to prevent that from happening?

  2. #2
    jmorgan is offline Getting Started on GPanswers.com
    Join Date
    Dec 1969
    Posts
    2

    Default

    I found out by the same process that is what restricted group does, it replaces the contents with what you specif... was not suitable for me for the same reasons, local user needed admin rights... so i just used the manage function in Active Directory Users and Computers proggie to insert my userid into their admin location.

    Hope this helps... i am still looking at other alternatives.

  3. #3
    jmorgan is offline Getting Started on GPanswers.com
    Join Date
    Dec 1969
    Posts
    2

    Default

    I found out by the same process that is what restricted group does, it replaces the contents with what you specif... was not suitable for me for the same reasons, local user needed admin rights... so i just used the manage function in Active Directory Users and Computers proggie to insert my userid into their admin location.

    Hope this helps... i am still looking at other alternatives.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search Engine Friendly URLs by vBSEO