Local Administrator & Local GPO on a workgroup computer

  • Thread starter Thread starter DCA
  • Start date Start date
D

DCA

We want to implement a GPO but not have it affect the local administrator
account on each machine.

We're looking for an easier way to engage the GPO w/out having to resort to
copy the registry.pol file everytime we need to make a small change.
Currently the method is cumbersome at best and leaves a lot of room for
error. I recalled seeing a post about denying read access to the local
admin account/group but can't seem find again. I'm not sure if it works
only in domain environment. We only have Win2000 and no WinXP machines.
Thanks in advance.
 
Thanks for the quick reply. The only thing that should added is to deny
both read & execute permissions as well. Otherwise, thanks again...really
appreciate it.
 
Can't you go to the properties of the domin
policy>security tab and remove the check for apply group
policy, or deny apply group policy, to the admistrators
group?


-----Original Message-----
293655 HOW TO: Apply Local Policies to all Users Except Administrators on
http://support.microsoft.com/?id=293655

--
Richard McCall [MSFT]

"This posting is provided "AS IS" with no warranties, and confers no
rights."
DCA said:
Thanks for the quick reply. The only thing that should added is to deny
both read & execute permissions as well. Otherwise, thanks again...really
appreciate it.


the local
administrator
w/out having to
resort leaves a lot of room
for access to the
local not sure if it
works and no WinXP
machines.

.
 
Back
Top