swpa_wnt
asked on
Restricted Group
I want to create a Restricted Group for the local machines on my Domain. The reason for this is as follows. All of my domain users have local admin rights on their PC. Some of my users, not a lot, have been removing the Administrator and Domain Admin accounts from the Local Admin Groups on their PC and I want to force this issue to a screatching hault. I could use a Net local group command which would add the Domain Admin group to the local administrator account and push it with a logon script but I don't want to go that route. What I want to do is impliment a Restircted Group via a GPO that will add the Domain Admin group to the users "Local Admin" group thus preventing my problem.
I have a test network I've tried this on but I can't seem to get the Domain Admin group added to the "Local Admin" group with the policy I'm creating.
I have a test network I've tried this on but I can't seem to get the Domain Admin group added to the "Local Admin" group with the policy I'm creating.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.