Solved

Configure restricted Group with GPO

Posted on 2011-02-14
2
514 Views
Last Modified: 2012-05-11
Hello i need help with my GPO SETTING in my enterprise (single forest) i have techninician people who when they join a computer to the domain they put it in the Computer container and give the users Local Administration rights on the computer. so to avoid that i created an OU called Stock and now i want to design a GPO so that these TECH GUYS WHO BELONG TO particularSecurity group won't be able to put the users as Local Administrator of their computer when it's inside the STOCK OU. I don't want them to be able to do any thing to the computer once the Computer is in that OU
I know i can use restricted Group but i'm confuse about the Group and member Of interface

I need help on my GPO settings, Delegations etc ....
Thank you
0
Comment
Question by:LI20579
2 Comments
 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 34890873
Take a look at this post, i think this is one of the better posts about restriced groups. It sounds like you want to force the members of the local admin group so you would add all the groups and users into "Members of this Group"

http://www.frickelsoft.net/blog/?p=13
0
 

Author Closing Comment

by:LI20579
ID: 35081312
Good enought
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Roaming Profiles 8 60
Exchange 2013 Message Loop 7 31
Authentication type 1 24
What is this Task? 4 38
Mapping Drives using Group policy preferences Are you still using old scripts to map your network drives if so this article will show you how to get away for old scripts and move toward Group Policy Preference for mapping them. First things f…
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now