O
Olu Daniels
I have 1200 Windows XP workstations on a newly migrated Windows 200 Active
Directory domain (Migrated from NT 4.0 to Win2K AD). We have about 70 domain
local groups that are member of local administrators group on different
Windows XP computers (running SP1). Different users belong to different
domain local groups. We have decided that we do not want this groups to be
member of the local admin groups on the Win XP anymore because we do not
want the users to have administrative privilege or be members of the local
administrator's group on the Win XP computers.
Is there a way to set this as a GPO on the domain controllers or a script
to add to the startup script that will automate this, instead of doing it
manually on each computer?
Thanks
OD
Directory domain (Migrated from NT 4.0 to Win2K AD). We have about 70 domain
local groups that are member of local administrators group on different
Windows XP computers (running SP1). Different users belong to different
domain local groups. We have decided that we do not want this groups to be
member of the local admin groups on the Win XP anymore because we do not
want the users to have administrative privilege or be members of the local
administrator's group on the Win XP computers.
Is there a way to set this as a GPO on the domain controllers or a script
to add to the startup script that will automate this, instead of doing it
manually on each computer?
Thanks
OD