Re: remove local admin right in 200 client computer



You could use Group Policy Restricted Groups using "members of this group"
to enforce membership of the local administrators group. When applied only
the users/groups specified will be in the local administrators group on the
domain computers within the scope of the Group Policy and other users/groups
will be removed with the exception of the built in administrator account and
I suggest including domain admins also as member of the included groups. The
link below explains in detail how to use Restricted Groups and I suggest
that you create an Organizational Unit to configure it for and then move the
computer accounts you want to affect into that OU which can be a child OU of
an existing OU. I don't recommend using Restricted Groups at the domain
level as you run the risk of affecting domain controllers, etc if not done
correctly.

Steve

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html ---
Restricted Groups

"Alexander Brown" <alexanderbrown@xxxxxxxxxxx> wrote in message
news:%23FsbdTSEIHA.4400@xxxxxxxxxxxxxxxxxxxxxxx
Dear all,

We are a middle-size company around 200 staffs. For improve the security
control, we are planning to remove all user local admin right in their
computer. Any logon script, group policy or registry can help us to remove
local admin right in our user computer?

Best regards,

Alexander



.



Relevant Pages

  • Re: Group Manipulation
    ... You could either use a Group Policy "startup" script with the net localgroup ... administrators command or use Restricted Groups. ... are two distinct options - members of this group and members of this group. ...
    (microsoft.public.windows.group_policy)
  • RE: SavingMaintaining group members
    ... > It's called restricted groups within group policy. ... >> swear I have seen or read somewhere that you can protect a group such as a ... >> only allows groups to be members and that if you did put a user into the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group Manipulation
    ... > localgroup administrators command or use Restricted Groups. ... > at the OU level and NOT the domain level. ... > Note there are two distinct options - members of this group and members of ... >> Is it possible to use group policy to assign a domain group to be a local ...
    (microsoft.public.windows.group_policy)
  • Re: Group Manipulation
    ... Sure you could use Restricted Groups. ... the Group Policy with Restricted Groups as long as you don't mind all those ... users being local administrators on all those computers keeping in mind that ... >> are two distinct options - members of this group and members of this ...
    (microsoft.public.windows.group_policy)
  • Re: Add Domain Admin to local XP Admin group
    ... When you join a machine to the domain, the Domain Admins group are made ... members of the local Administrators group of the machine by default. ... group policy so I don't have to do it on ever PC I have? ...
    (microsoft.public.windows.server.active_directory)