Group Policy controlling local administrators membership on workstation


domain has 2008 2003 , 2000 domain controllers. workstations xp, have sp1,some sp2, , sp3. possible group policy have logged on user member of local administrators group without being member on workstations?
before conficker domain users member of local administrators group , world happier place. applied group policy make local administrator , domain tech group members of local administrators group , after period of time removed group policy , local administrators group membership reverted pre conficker members, i.e. domain users member of local administrators group. 

thanks help

hi,
yes, using restricted groups in group policies can add interactive administrators group. logged on user have administrative rights.
remember add domain admins too.
jens ole kragh mcitp, mcts, mct http://jensolekragh.spaces.live.com/


Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file