Link to home
Create AccountLog in
Avatar of srinivaskakumanu
srinivaskakumanu

asked on

Local Admin rights through Server 2003 GPO

Hello All

Our Helpdesk is stating that computers in a certain OU where individual domain accounts are part of Local administrator group are being removed. I checked GPO setting but not sure where to look in particular.

I need to make sure that what ever user account is added as local admin should stay there and not over written by GPO.

Thanks
Avatar of bigbigpig
bigbigpig

Run a rsop to see what's being enforced.

gpresult /z > result.txt

Open in new window


Look under the section "Restricted Groups".  This will tell you what's being enforced by which GPO.
Avatar of srinivaskakumanu

ASKER

I ran the command but it says N/A under Restricted Groups.
Check for scripts. I had a similar case that local Administrators group were been manage by a computer startup script.
Checked do not see anything there.

Can you please provide steps to create a new GPO and apply it to a security group so that they can have local administrator access on a OU which contains some computers.

Thanks
ASKER CERTIFIED SOLUTION
Avatar of bigbigpig
bigbigpig

Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Thanks :)