filip said:
Thx for advice, but still need to add some to be admins, if oyu could pls.
advise me on how to do this. I found something on the net, but did not
work for me.
This is what i found
Edit the GPO, navigate to:
Computer configuration, Windows Settings, restricted groups
in the right pane right-click and choose "Add group..."
In the Add Group dialog type "Administrators"
Click OK
Click Add to the right of "Members of this group"
In the add member dialog type:
Administrator;DOMAINNAME\Domain Admins; DOMAINNAME\SUPPORT <---replace
DOMAINNAME for your Domain name, replace SUPPORT for the name of your
group.
But do not know if this is what i have to do on local or domain controller
pls advise on how to manage this thx
What you tried is backwards, that is, unless you really did want to
completely redefine the membership in the Administrators group.
If one had an OU named X with a couple dozen machines in it, and
you defined a custom domain group OuXadmins that you wanted to
be in the Administrators group of all machines in OU X, and you
did not want to totally replace what is already in each machine's
Administrators group, here is what you need to do.
Define (or use existing) GPO that is linked to OU X
In that OU define a restricted group for OuXadmins.
Do not touch the Members list of the restricted group definition.
Instead, only add Administrators to the "Member of" list.
For this to work, the machines must be at minimum of XP SP2,
Windows 2000 SP4, or above (W2k3/W2k3 R2/Vista)
The effect is that OuXadmins group will be added into the
membership of Administrators group on each machine, and
no other change will be made.
However, again I also caution you, do not use this for the
purpose you have stated. That would be like intentionally
decising to drive the wrong way on a one way street.
Roger