Restricted Groups Issue

  • Thread starter Thread starter Lee Messenger
  • Start date Start date
L

Lee Messenger

Hi,

I am using the Restricted Groups feature to give my helpdesk personnel admin
access to all the users PC for support purposes.

I also have some users that require admin access to their PC as well. If I
make a group for these users then add them to the restricted groups policy,
these users will be admins on all the PC's in the OU is linked to.

This means these users will be able to get to the c: drive of all the PC's
in the OU.

Is there any way of stopping local administrators from browsing to other
computers c$ shares ?

TIA

LM
 
For those users add their domain users account individualy to the local
administrator account on their computer only. --- Steve
 
Steven,

If I do that, the restricted group policy will over-write what I do
manually.

For example, if I make my helpdesk group members of the local administrators
group using a GPO, if I then modify the local admin group on the PC, the
GPO settings will remove the manual modifications on the next reboot.

Regards,
 
Good point. You may need to move those computers into an OU that does not
have a restricted groups setting and manually configure the local
administrator account with both the user and help desk group. You could do
it remotely via Computer Management. -- Steve
 
Back
Top