troubleshooting Question

Disallow group policy actions on local computer joined to domain

Avatar of Swift
Swift asked on
SecurityActive DirectoryWindows 7
10 Comments3 Solutions520 ViewsLast Modified:
Assuming we have a domain user acccount and the account is part of local Administrators group, post joining a Windows 7 Ent desktop to a 2003 domain, there is a need to accomplish the following:

- Disallow creation / addition of any other service or individual domain users / groups via Domain Admins and related group policies settings within AD.

Can this be accomplished using local windows firewall or group security policy settings to override domain administered policies ?
ASKER CERTIFIED SOLUTION
Krzysztof Pytko
Senior Active Directory Engineer
Join our community to see this answer!
Unlock 3 Answers and 10 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 3 Answers and 10 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros