?
Solved

gpo help

Posted on 2014-10-16
2
Medium Priority
?
203 Views
Last Modified: 2014-10-20
Hello Experts

I need from your expertise in creating a new GPO to allow an AD group named G_VDI_BIAdmin to be local system admins for all laptops under OU named VDI Desktops

My environment

Windows 2003 DCs, forest/domain functional level 2003

Clients  Windows 7 SP1
0
Comment
Question by:Jerry Seinfield
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 16

Accepted Solution

by:
Joshua Grantom earned 2000 total points
ID: 40384300
1. Create a new GPO
2. Name it whatever you want
3. Add G_VDI_BIAdmin as Restricted Group in Computer Configuration -> Policies -> Windows Settings -> Security Settings --> Restricted Groups in your new GPO
4. In G_VDI_BIAdmin Restricted Group Properties window click add and under the This group is member of, type "Administrators"
5. Link this GPO to the OU "VDI Desktops"
6. Wait for the policy to apply.

Done.
0
 
LVL 13

Expert Comment

by:Rizzle
ID: 40384305
This can be achieved by using the Restricted Groups option in Group Policy.

This should be able to help: http://community.spiceworks.com/how_to/show/2123-add-an-active-directory-group-to-the-local-administrator-group-of-workstation-s
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses
Course of the Month11 days, 22 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question