Solved

Need to revoke local admin rights for all users - domain-wide using GPO.

Posted on 2014-12-02
2
240 Views
Last Modified: 2015-01-02
Currently users have local admin rights and this is no longer necessary.  What's the best and easiest method to change a current user who's a local admin to a regular user.  Thanks.
0
Comment
Question by:LB1234
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 10

Accepted Solution

by:
Walter Padrón earned 250 total points
ID: 40476904
Open the Group Policy Management console and create a new GPO

Under Computer configuration > Windows Settings > Security Settings > Restricted Groups add the local  Administrators group, if you setup the "Members of this group " portion of the policy, it will remove anything else that is listed locally. It will only apply the group that is in your policy.

** Make sure to get the "Domain Admins" group added and the policy added to computers OU

Best regards
0
 
LVL 15

Assisted Solution

by:Rob Stone
Rob Stone earned 250 total points
ID: 40477033
Another method is to use GPP which offers more flexibility.  This post offers a really good overview of how you can use it to dynamically assign users local admin with item-targeting or by using AD Groups.

http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question