Group policy management machine

  • Thread starter Thread starter Gunna
  • Start date Start date
G

Gunna

Hi I keep reading how MS recomend setting up a dedicated machine as a GP
management machine so other administrators on their local machines can't
screw up the GP etc. How do I do this and how do I assign that one PC as
the only PC that can make GP changes?
 
Hi,

Not sure what you mean by this. Local Administrators cannot screw up Group
Policy. The only people who have access to Change Group Policy in a Domain
are the Domain Administrators. Other than that you can "delegate" specific
control to certain users to do certain tasks like change passwords or add
users to specific OU's. However this is user specific not domain specific.

Clients don't even have the Group Policy software installed so they cannot
even see Group Policy without that software.

Cheers,
Lara
 
Back
Top