Group Policy controlling local administrators membership on workstation


domain has 2008 2003 , 2000 domain controllers. workstations xp, have sp1,some sp2, , sp3. possible group policy have logged on user member of local administrators group without being member on workstations?
before conficker domain users member of local administrators group , world happier place. applied group policy make local administrator , domain tech group members of local administrators group , after period of time removed group policy , local administrators group membership reverted pre conficker members, i.e. domain users member of local administrators group. 

thanks help

hi,
yes, using restricted groups in group policies can add interactive administrators group. logged on user have administrative rights.
remember add domain admins too.
jens ole kragh mcitp, mcts, mct http://jensolekragh.spaces.live.com/


Windows Server  >  Group Policy



Comments

Popular posts from this blog

Round Robin is killing performance on our network

WMI Repository 4GB limit - Win 2003 Ent Question

Change home folder default permission?