Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

How to restrict Group policy administration to a specific domain user/group

Posted on 2014-11-02
3
Medium Priority
?
104 Views
Last Modified: 2015-06-18
We have Windows 2003 Domain controller and we have couple of Domain/Enterprise admins. How to restrict Group policy administration to a specific domain user/group?
0
Comment
Question by:psanjoy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 13

Expert Comment

by:Rizzle
ID: 40418081
Check out this article from Microsoft on group policy management! But by default domain admins can create, amend and delete policies, maybe worth look into whether they definitely need domain admin rights?

http://technet.microsoft.com/en-us/library/cc754948(v=ws.10).aspx
0
 

Author Comment

by:psanjoy
ID: 40418918
domain admins  and enterprise admins should not have access to GP management except the Local Admin/ a specific user. pls help me
0
 
LVL 13

Accepted Solution

by:
Rizzle earned 1500 total points
ID: 40420108
ok I got you now,

try the solution listed in this Microsoft article which restricts access to specific admins to Group Policy.

https://social.technet.microsoft.com/Forums/windowsserver/en-US/59ebdb08-57f0-4e22-928f-a2f5fd3d5bdf/restrict-group-policy-editing-to-a-group-of-domain-admins?forum=winserverGP
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question