Link to home
Start Free TrialLog in
Avatar of psanjoy
psanjoyFlag for United Arab Emirates

asked on

How to restrict Group policy administration to a specific domain user/group

We have Windows 2003 Domain controller and we have couple of Domain/Enterprise admins. How to restrict Group policy administration to a specific domain user/group?
Avatar of REIT
REIT

Check out this article from Microsoft on group policy management! But by default domain admins can create, amend and delete policies, maybe worth look into whether they definitely need domain admin rights?

http://technet.microsoft.com/en-us/library/cc754948(v=ws.10).aspx
Avatar of psanjoy

ASKER

domain admins  and enterprise admins should not have access to GP management except the Local Admin/ a specific user. pls help me
ASKER CERTIFIED SOLUTION
Avatar of REIT
REIT

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial