Can you prevent User and Group Admin, from a User in local admin group?

From: WantoKnow (WantoKnow@WantoKnow.com)
Date: 01/31/03


From: "WantoKnow" <WantoKnow@WantoKnow.com>
Date: Fri, 31 Jan 2003 09:35:10 -0800


Can you prevent User and Group Admin, from a User in
local admin group?
I.E; a policy that prevents a specific User from adding
or deleting accounts eventhough they are a part of the
local admin group.



Relevant Pages

  • Re: Group policy tatooing with restricted group ? or strange behaviour !
    ... Run after the 3rd change when the user is logged in rsop and check if the policy is apllied with the correct setting. ... the configuration 3 deleted the user account that was in the admin ... account is present in the local admin group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Configure a Global Group to Be a Member of Local Administrator Gro
    ... that contains your computer accounts. ... that are not part of the policy are removed ... Use startup script (defined trough GPO) on your computers, ... This will add yourgroup to local Admin group on your PC. ...
    (microsoft.public.win2000.active_directory)
  • Re: Using GP to assign groups to local admin group
    ... I am assuming that you are using Restricted Groups in GP to specify which ... group during a policy refresh. ... something like Domain Users to the local admin group. ... > our computers (they manipulate the computer portion). ...
    (microsoft.public.win2000.group_policy)