GPO's and Security

From: Russ (russ@removemeruss.net)
Date: 04/08/03


From: russ@removemeruss.net (Russ)
Date: Tue, 08 Apr 2003 21:35:23 GMT


I am trying to figure out how to give my administrators in the field
local admin access to the PCs in their OU. I followed these steps
below:

1- Create Domain Global Group: admins2
2- Create a GPO
3- Add "adminstrators" built-in group
4- Add your "IT Staff" accounts in this "administrators" group
5- Give read/apply permissions to the set of workstations that you
want the "IT Staff" accounts to be part of the built-in local
administrators group
6- Apply the GPO to the OU containing the workstations
7- Reboot the target workstations

The problem is when you apply the GPO it wipes out whatever was in the
local admins group before. What you end up with is only those users
or groups that were specified in the GPO inside the local admins
group. The GPO works like a champ and would be a solution if we
didn't have users who required admin rights to their machines. If you
add them to the GPO to give them rights to their own machine, you also
give them admin rights to every other machine in the OU. A work
around would be to segregate machines into different OU's and apply
different GPO's to each one, but what a nightmare to administer!

There's gotta be a simple solution?



Relevant Pages

  • Re: Domain Users to have Local Admin rights
    ... all machines that are with scope of the GPO carrying the Restricted ... their local Administrators group. ... We have various admin accounts other then administrator ...
    (microsoft.public.windows.server.security)
  • Re: gpo for local admin restrictions
    ... Administrators cannot be prevented from performing this task. ... > removing themselves from the domain and I want to put a stop to this. ... > doing this (they all must remain as local admins though). ... > in AD but couldn't find any GPO that does this. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Rights to local machine
    ... Inside of GPOs there is Restricted Groups node. ... If in a GPO linked to an OU containing the machines ... should be in the Administrators group on impacted ...
    (microsoft.public.windows.group_policy)
  • Re: Add additional domain group to local admins groups?
    ... If your machines are all at the current service pack level then a fix is ... but assuming that you understand that to add a group to Administrators ... Restricted Group in an OU impacting that OU, ... We need to add new default local admins without removing the local admins ...
    (microsoft.public.windows.group_policy)
  • Re: Help needed setting up roaming administrator
    ... >Administrators group (just type in Administrators, don't browse for it, ... >add your Roaming Local Admins group to the Members of this group section ... GPO associated with the OU that contains the computers I want to use ... restricted group and to define the groups the restricted group will ...
    (microsoft.public.win2000.security)