dsulli2000
asked on
Restricted Groups GPO's, adding a user to local Admins
Hello,
I have a question about restricted group policy objects. Perhaps I'm just not sure they way that they actually work. Basically, I have a domain, lets call it DOMAIN. I have a domain group called SHOULDBELOCALADMINS. Basically, I want the domain group to be local administrators on all of the workstations found in OU WORKSTATIONOU. So basically, I though t "Ok, I'll just use a restricted group GPO and be done with it". But upon further investigation it appears that a restricted group will remove all other accounts from local admins. I don't want to do that. Basically, I want to add an additional group to local administrators of every workstation in a given OU without removing any object already existing in local administrators of the workstation(s). Does anybody know how to do this? I know this can be done progmatically with a script but I want to do it with a GPO.
Thanks,
Dan
I have a question about restricted group policy objects. Perhaps I'm just not sure they way that they actually work. Basically, I have a domain, lets call it DOMAIN. I have a domain group called SHOULDBELOCALADMINS. Basically, I want the domain group to be local administrators on all of the workstations found in OU WORKSTATIONOU. So basically, I though t "Ok, I'll just use a restricted group GPO and be done with it". But upon further investigation it appears that a restricted group will remove all other accounts from local admins. I don't want to do that. Basically, I want to add an additional group to local administrators of every workstation in a given OU without removing any object already existing in local administrators of the workstation(s). Does anybody know how to do this? I know this can be done progmatically with a script but I want to do it with a GPO.
Thanks,
Dan
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Netmann
Yeah, I copied your comments . >:)
Yeah, I copied your comments . >:)
You can do both - either remove and replace the group membership or add members to a group.
You want to use the option of adding groups to other groups.
The above will work.