Solved

Group Policy to remove Domain\Local Admin

Posted on 2011-09-23
6
232 Views
Last Modified: 2012-05-12
I am looking for a Group Policy to remove DomainName\Local Admin  from my workstations. Attached is a screen shot of the Local workstation, Computer Management, Local usere and groups, Administrators  with the Member I want to remove from my domain workstations.

Thank you  [
local-admins.jpg
0
Comment
Question by:Randy Madej
  • 3
  • 2
6 Comments
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36586499
Use within that GPO node named Restricted Groups. You can read more abot that in the Internet because it's inconvenient placing links on a mobile ;)

If you have at least one Win7/2008 you can use Group Policy Preferences for that, but firstly you need to install Client Side Extension on XP/ 2003 machine. I will post links a little bit later or you can google for that. Thanks

Regards,
Krzysztof
0
 

Author Comment

by:Randy Madej
ID: 36586555
The networi is most xp machines I have 4 Win 7 and all servers are 2003
0
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 500 total points
ID: 36586667
So, in my opinion it's better to use GPP. Instal CSE on each XP/2003 and create GPP on a 7 import to 2003 GPO and link to OU(s).

GPP information aboy that
http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/

CSE for XP
http://www.microsoft.com/download/en/details.aspx?id=3628

CSE for 2003
http://www.microsoft.com/download/en/details.aspx?id=6955

you can install that update from WSUS

If you don't want to use GPP, then use Restricted Groups
http://www.windowsecurity.com/articles/using-restricted-groups.html
http://technet.microsoft.com/pl-pl/library/cc756802%28WS.10%29.aspx

Krzysztof
Krzysztof
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 
LVL 23

Expert Comment

by:Stelian Stan
ID: 36586687
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36586717
Nope, this link from Mike's blog is for filtering GPO appliance :) He needs to restrict membership of local Administrators group on a server/PC :]

Krzysztof
0
 
LVL 23

Expert Comment

by:Stelian Stan
ID: 36586734
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Problem pinging RRAS server from outside the network 11 88
clearing an obsolete 2003 server from our domain 8 72
Connecting two servers 30 83
2003 Server DNS/FS errors 6 52
So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question