Group Policy controlling local administrators membership on workstation
domain has 2008 2003 , 2000 domain controllers. workstations xp, have sp1,some sp2, , sp3. possible group policy have logged on user member of local administrators group without being member on workstations?
before conficker domain users member of local administrators group , world happier place. applied group policy make local administrator , domain tech group members of local administrators group , after period of time removed group policy , local administrators group membership reverted pre conficker members, i.e. domain users member of local administrators group.
thanks help
yes, using restricted groups in group policies can add interactive administrators group. logged on user have administrative rights.
remember add domain admins too.
jens ole kragh mcitp, mcts, mct http://jensolekragh.spaces.live.com/
Windows Server > Group Policy
Comments
Post a Comment