Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Policy to remove existing group in local adminstrator group

Posted on 2013-05-20
5
Medium Priority
?
273 Views
Last Modified: 2013-06-05
Is there a way to remove existing group in the local adminstrator group using group policy?
0
Comment
Question by:dongocdung
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 22

Accepted Solution

by:
Joseph Moody earned 1600 total points
ID: 39181610
Yep. Use restricted groups:

http://www.frickelsoft.net/blog/?p=13
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 400 total points
ID: 39181636
Just to follow on jmoody, notice that there are two boxes, in your case you will want to use the top box "members of this group" and define who you want to be in the local admin group.

Test first and get a feel for it before deploying to production.

Thanks

Mike
0
 

Author Comment

by:dongocdung
ID: 39181685
This is the scenerio:

1) Administrators groups have 3 groups:

    . contoso/domain admins
    . contoso/help-desk
    . yoda

2) We want to remove all three of these existing groups and put in a new one.

   contoso/admin

How do we accomplish this?
0
 

Author Comment

by:dongocdung
ID: 39184678
Anyone has any update?
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 39185241
Did you read the link above? It shows you how to do this.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
A hard and fast method for reducing Active Directory Administrators members.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question