Solved

Restricted Groups Problem

Posted on 2011-09-25
4
270 Views
Last Modified: 2012-06-21
Greetings,

I am working with WIN2008 Enterprise active directory.

I recently wanted to make one regular domain user a local admin on certain workstations and I did accomplish that by using Restricted Groups.

The thing now is, I want one more local admin to help the first one. But I did not want the new one to be added to the same Restricted Group which the first one is in.

I went on and made another GPO and named it 2ndlocaladmin and went to Restricted Groups and added a group and named it Administrators inside. And then went to its properties and I added that new domain user to this newly created group.

When I went on to link this GPO to the workstations group wanted, nothing happend.

Neither the domain admin nor the new GPO worked and I had to remove the GPO.

Is there a problem for having two different Restricted Groups GPOs in the same domain, knowing that the two are not applied to the same computers "workstations" group > meaning is that the two are not linked to the same computers group at the same time, each one is linked to a different computers group.

And what could it be that am doing wrong here?

Thank you
0
Comment
Question by:ksssg
  • 2
  • 2
4 Comments
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 500 total points
ID: 36595090
I would suggest to remove Restricted Groups GPO and use Group Policy Preferences (GPP) for that. It's much more easy in use and it's newer option since 2008/Win7

More about this method at
http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/

If you need to apply GPP to XP/2003 clients, you need to install Client Side Extension (CSE), first. It can be downloaded from

for XP
http://www.microsoft.com/download/en/details.aspx?id=3628

for 2003
http://www.microsoft.com/download/en/details.aspx?id=6955

or you can push this update from WSUS.

Regards,
Krzysztof
0
 

Author Comment

by:ksssg
ID: 36595618
I LOVE YOU iSiek, I LOVE YOU SO MUCH lol. You see, the second I see your nickname I just know I will find an answer, and not any answer, the absolute ONE good answer there lol.

Yep, a True Genius

Thank you so much
0
 

Author Closing Comment

by:ksssg
ID: 36595622
What can I say, iSiek is a Genius!.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36595653
Thank you for compliment :)

Krzysztof
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
WriteBack Attribute permission on domain level 13 57
windows 7 login times take 30 minutes with AD 8 46
Regarding Ad Connect Users Access 5 27
Admin account lockout 10 35
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

816 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now