GPO and Local Administrator

Posted on 2008-11-14
Medium Priority
Last Modified: 2012-05-05
So I have a very strict environment but want to allow users to install things like EXCEL add-ons and potentially install programs.  So just curious, if I add the users to the restricted groups portion of the gpo will they be able to overrride many of the s tricter settings I have such as not being able to map/unmap drives, can't see any local drives, etc that i have set?  Guess the big question is will a local admin be able to override domain wide GPO settings?

Question by:dlabbadia01

Accepted Solution

pzozulka earned 300 total points
ID: 22963797
Local admin will not be able to overide any GPO settings of the GPO on a grand scheme. Basically local admin will not affect the GPO settings on the network or any other machines. However, Local Admins have full control of machines regardless of GPO settings.
LVL 14

Assisted Solution

dfxdeimos earned 200 total points
ID: 22963912
Question: Will a Local Admin be able to override domain wide GPO settings?

Answer: Depends. On settings that affect how he /she interacts with that specific computer then the answer is yes. However the Local Admin account on any one machine only has authority over that machine, and cannot affect policies that prevent access to network resources / items not controlled by the machine.

Author Comment

ID: 22963989

I'll wing it and see what happens.   I'm not worried about network access, more what they do to their virtual desktops.  Right now they can't do anything at all but I need to loosen it up so trying to find the right balance.  Will award you both some pointizzles.


Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question