Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 217
  • Last Modified:

gpo help

Hello Experts

I need from your expertise in creating a new GPO to allow an AD group named G_VDI_BIAdmin to be local system admins for all laptops under OU named VDI Desktops

My environment

Windows 2003 DCs, forest/domain functional level 2003

Clients  Windows 7 SP1
0
Jerry Seinfield
Asked:
Jerry Seinfield
1 Solution
 
Joshua GrantomSenior EngineerCommented:
1. Create a new GPO
2. Name it whatever you want
3. Add G_VDI_BIAdmin as Restricted Group in Computer Configuration -> Policies -> Windows Settings -> Security Settings --> Restricted Groups in your new GPO
4. In G_VDI_BIAdmin Restricted Group Properties window click add and under the This group is member of, type "Administrators"
5. Link this GPO to the OU "VDI Desktops"
6. Wait for the policy to apply.

Done.
0
 
RizzleCommented:
This can be achieved by using the Restricted Groups option in Group Policy.

This should be able to help: http://community.spiceworks.com/how_to/show/2123-add-an-active-directory-group-to-the-local-administrator-group-of-workstation-s
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now