Local Admin Rights Delegation to Windows 7 Clients, but not to DC


hi folks

i having 6 domain controllers site wide , few domain admin each location. want delegate local admin rights other admin access same desktop local admin rights.

i delegated group list of members , added them respective ou have access in each sites. if these members login domain controller local admin rights reflect gaining access dc.

any idea how can restrict this? or missed configurations control windows 7 admins not have access dc?


cheers

mohamed ibrahim nowshad


hi,

please follow below steps denying logon dc members of group,

for example deny dc logon members of group "dc deny logon group",

- create group policy object (gpo) linked @ "domain controllers" ou  called "dc deny interactive logon".
- right click , edit gpo "dc deny interactive logon" , navigate node "computer configuration\windows settings\security settings\local policies\user rights assignment".
- in "user rights assignment" node add "deny log on locally" permission "dc deny logon group" group.

regards,
gopi
www.jijitechnologies.com



Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file