Link to home
Start Free TrialLog in
Avatar of dsulli2000
dsulli2000

asked on

Restricted Groups GPO's, adding a user to local Admins

Hello,

I have a question about restricted group policy objects.  Perhaps I'm just not sure they way that they actually work.  Basically, I have a domain, lets call it DOMAIN.  I have a domain group called SHOULDBELOCALADMINS.  Basically, I want the domain group to be local administrators on all of the workstations found in OU WORKSTATIONOU.  So basically, I though t "Ok, I'll just use a restricted group GPO and be done with it".  But upon further investigation it appears that a restricted group will remove all other accounts from local admins.  I don't want to do that.  Basically, I want to add an additional group to local administrators of every workstation in a given OU without removing any object already existing in local administrators of the workstation(s).  Does anybody know how to do this?  I know this can be done progmatically with a script but I want to do it with a GPO.

Thanks,

Dan
ASKER CERTIFIED SOLUTION
Avatar of life_j
life_j

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Netman66
Looks suspiciously like something I typed. :o)

You can do both - either remove and replace the group membership or add members to a group.

You want to use the option of adding groups to other groups.

The above will work.

Avatar of life_j
life_j

Netmann

Yeah, I copied your comments . >:)