Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Local admin group policy challenge!

Posted on 2011-02-18
3
Medium Priority
?
273 Views
Last Modified: 2012-06-27
I have a relatively small domain of 20 XP Pro workstations and 1 windows Server 2003 Standard DC.
Each user is a local admin because domain users are in the local admin group of each workstation. Is there a way to reverse this without going to each station? - the last couple of viruses have made us much more security aware. I want to turn users back to normal users to prevent software installations.
0
Comment
Question by:HardwareDude
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 34927043
Great idea, you don't need them to be local admins.

You can use restricted groups to do this.  Florian has a great writeup   http://www.frickelsoft.net/blog/?p=13

So as you can see you can either wipe out what is there and start fresh or add/append to what is there.

in your case I'd start fresh and define what you want.

Get a feel for it by testing on your box or a test machine first.

Thanks

Mike
0
 
LVL 3

Expert Comment

by:andreibutu
ID: 34927062
NET LOCALGROUP administrators UserName /delete

change UserName with required name & use this command in batch file.
0
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 34927225
Restricted groups is the better option because it enforces the setting through time as opposed to just making just a one time change.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question