Need help with Active Directory policies

Our intentions are to secure our windows XP machines, we are a large company using active directory on Server 2003.  We are trying to prevent domain users with local admin rights from creating a local account and being able to remove the PC from the domain.   We have removed the user accounts shortcut from control panel and locked down Local users and Groups in computer management and the MMC console and restricted the use of Regedit.  We need to accomplish two more things and I think we will have accomplished our goal.  

First prevent the use of the Net User command or any other command that can be used to create an account at the command line.  So that is my first question.  How do I do that using active directory?

Second, there is a post on this site that says you cannot prevent a local admin from removing a pc from the domain.  I am thinking that if I can use a policy to remove the computer name tab from System Properties  I will have essentially accomplished this.  Am I wrong?  And if this will work how do I do it?
pcs1111Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Jay_Jay70Commented:
i dont think you can block that net user command using GP - you may need to block off access to the run command console itself. there is a policy which restricts the use of certain applications that you specify, but if users have access to the cmd then they can run them from there.....

Administrative Templates\System\Prevent access to the command prompt


you also cant gide specifially the computer name TAB itself you will need to block the entire properties menu from my computer

User Config\Admin Templates\Desktop\Remove the properties from the my computer context menu
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.