Local Admin Rights Delegation to Windows 7 Clients, but not to DC
hi folks
i having 6 domain controllers site wide , few domain admin each location. want delegate local admin rights other admin access same desktop local admin rights.
i delegated group list of members , added them respective ou have access in each sites. if these members login domain controller local admin rights reflect gaining access dc.
any idea how can restrict this? or missed configurations control windows 7 admins not have access dc?
cheers
mohamed ibrahim nowshad
hi,
please follow below steps denying logon dc members of group,
for example deny dc logon members of group "dc deny logon group",
- create group policy object (gpo) linked @ "domain controllers" ou called "dc deny interactive logon".
- right click , edit gpo "dc deny interactive logon" , navigate node "computer configuration\windows settings\security settings\local policies\user rights assignment".
- in "user rights assignment" node add "deny log on locally" permission "dc deny logon group" group.
regards,
gopi
www.jijitechnologies.com
Windows Server > Group Policy
Comments
Post a Comment