Link to home
Start Free TrialLog in
Avatar of MilesLogan
MilesLoganFlag for United States of America

asked on

Remove domain accounts from local Administrators group

Hi EE

Does anyone have a script that removes domain accounts from the local administrators group on machines ?

So for instance if I have a list of machines and a list of domain accounts that I need removed from the local administrators
group on those machines .

Machine1,MyDomain\User1
Machine2,MyDomain\User2
Machine3MyDomain\User3
Avatar of Will Szymkowski
Will Szymkowski
Flag of Canada image

You will not be able to accomplish this. When you add a computer to the domain 2 things happen. Domain Admins Group is automatically added to the Local Administrators Group on all Domain Computers.  Also Domain Users is also added to the Local Users group as well.

So you cannot remove domain admins from local admins. You can remove the users from Domain Admins group which will then remove the access to local admins but you cannot remove Domain Admins completely.

So if i am reading your question correctly, what your asking for cannot be accomplished.

Will.
ASKER CERTIFIED SOLUTION
Avatar of oBdA
oBdA

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of MilesLogan

ASKER

Hi oBdA .. wow ! this so helped me today !! thanks a ton !