Re: problem with "Restricted Groups" within a GPO linked to my domain.



Restricted Groups does not prevent a user that can add members to a RG from
doing so. What RG will do however is to enforce membership of the RG at the
next Group Policy computer configuration refresh which for a domain
controller is no more then five minutes by default or you can force a
refresh at which time you should see the unauthorized user removed from the
RG. --- Steve


"Gregory Mode" <GregoryMode@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8E0CA82E-5DDB-42E0-AC39-29934002A5F3@xxxxxxxxxxxxxxxx
> I'm currently trying to set up "Restricted Groups" in my domain and I'm
> having problems (I think).
>
> From my understanding, when I define a group(s) within the "Restricted
> Groups" for a policy (that policy being linked to the domain, *enforced
> and
> *enabled) that group can no longer be modified (users cannot be added nor
> removed from that group in 'Active Directory Users and Computers' mmc).
>
> I defined 'Enterprise Admins' within "Restricted Groups," and for the
> Enterprise Admins, I defined one administrator user as a member of. I
> restarted the Server to have the policy take effect, signed on as totally
> different user with administrator privileges, and with that user account
> was
> able to add any user to the 'Enterprise Admins' group.
>
> What am I missing?
>


.



Relevant Pages

  • Re: Restricted Groups GPO
    ... The startup script could add the required groups to the local admin group on ... I've only used it to stipulate> what domain groups are members or what local groups - I didn't care that> nobody else could be a member;-) ... > I need to use the Restricted Groups policy setting to enforce> membership in the local Administrators group on member servers and> workstations by certain global groups ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help with my WMI
    ... You could use the "Restricted Groups" policy to add members to a "Restricted ... > I would like my script to Add a specified group to the pc's Local Admin ...
    (microsoft.public.win2000.group_policy)
  • Re: local admin-rights
    ... Group Policy with restricted groups should do the trick. ... local administrators group. ... added members each time the policy is reapplied. ...
    (microsoft.public.win2000.security)
  • Re: Want to add users to their local Admin group
    ... You can accomplish this using Restricted Groups feature of the Group Policy. ... policy - you control its membership ultimately - meaning, ... while Domain wide being part of the Domain Users. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Give user Admin rights to all PCs?
    ... With care you can use the GPO Restricted Groups to do this. ... CompAdmins) you create to be a member of Adminstrators ... restricted group for CompAdmins and use the Members ...
    (microsoft.public.windows.server.active_directory)