Solved

Restricted Groups Problem

Posted on 2011-09-25
4
266 Views
Last Modified: 2012-06-21
Greetings,

I am working with WIN2008 Enterprise active directory.

I recently wanted to make one regular domain user a local admin on certain workstations and I did accomplish that by using Restricted Groups.

The thing now is, I want one more local admin to help the first one. But I did not want the new one to be added to the same Restricted Group which the first one is in.

I went on and made another GPO and named it 2ndlocaladmin and went to Restricted Groups and added a group and named it Administrators inside. And then went to its properties and I added that new domain user to this newly created group.

When I went on to link this GPO to the workstations group wanted, nothing happend.

Neither the domain admin nor the new GPO worked and I had to remove the GPO.

Is there a problem for having two different Restricted Groups GPOs in the same domain, knowing that the two are not applied to the same computers "workstations" group > meaning is that the two are not linked to the same computers group at the same time, each one is linked to a different computers group.

And what could it be that am doing wrong here?

Thank you
0
Comment
Question by:ksssg
  • 2
  • 2
4 Comments
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 500 total points
ID: 36595090
I would suggest to remove Restricted Groups GPO and use Group Policy Preferences (GPP) for that. It's much more easy in use and it's newer option since 2008/Win7

More about this method at
http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/

If you need to apply GPP to XP/2003 clients, you need to install Client Side Extension (CSE), first. It can be downloaded from

for XP
http://www.microsoft.com/download/en/details.aspx?id=3628

for 2003
http://www.microsoft.com/download/en/details.aspx?id=6955

or you can push this update from WSUS.

Regards,
Krzysztof
0
 

Author Comment

by:ksssg
ID: 36595618
I LOVE YOU iSiek, I LOVE YOU SO MUCH lol. You see, the second I see your nickname I just know I will find an answer, and not any answer, the absolute ONE good answer there lol.

Yep, a True Genius

Thank you so much
0
 

Author Closing Comment

by:ksssg
ID: 36595622
What can I say, iSiek is a Genius!.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36595653
Thank you for compliment :)

Krzysztof
0

Join & Write a Comment

Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now