oBdA - Suggested that in related Q: http://www.experts-exchang
I still think thats the best idea too myself :-) All users are admins of local machines so can run as login script if decided does have to be scrit way. Suggested VBScript (or still restricted groups) as hit the 20 character limit on using net localgroup command way...
Not got time at the mo. to take this any further, just passing...
Steve
Main Topics
Browse All Topics





by: oBdAPosted on 2009-10-18 at 06:48:28ID: 25599841
No need to do that in a startup script; a "Restricted Groups" policy is more suitable to have control over group membership.
om/en-us/l ibrary/ cc7 56802(WS.1 0).aspx
om/kb/2793 01
Just add "SophosAdministrator" as restricted group in a GPO applied to the target machines, and put only "System" in the "This group has the following members" field.
Restricted Groups Policy Settings
http://technet.microsoft.c
Description of Group Policy Restricted Groups
http://support.microsoft.c