M
Mike
I noticed a GPO setting called Restricted Groups located
in Computer Configuration/Windows Settings/Security
Settings. It will allow you to define the membership of
a group on a local computer (i.e. Administrators). When
defining the membership, it is absolute. When GPO is
refreshed, any modifications to the membership are erased
(additions or subtractions). My issue is that I also
need to allow the user to have administrator rights to
the local machine. (I know... This is horrible, but a
battle I will not win!)
Anyway, the question relates to the other configuration
in the setting. It will force the membership of a group
to another group. This would allow me to force the
membership of a "technicians group" to the local Admins
group and still set the user to be a member. The problem
is since it is a GPO; it only applies to the computer in
the OU. Well the groups on the computer are local and
cannot be nested with other groups. Has anyone found a
purpose for this second configuration? Additionally, any
insight on how to solve the problem without manually
configuring the desktops would be most helpful.
Thanks,
Mike
in Computer Configuration/Windows Settings/Security
Settings. It will allow you to define the membership of
a group on a local computer (i.e. Administrators). When
defining the membership, it is absolute. When GPO is
refreshed, any modifications to the membership are erased
(additions or subtractions). My issue is that I also
need to allow the user to have administrator rights to
the local machine. (I know... This is horrible, but a
battle I will not win!)
Anyway, the question relates to the other configuration
in the setting. It will force the membership of a group
to another group. This would allow me to force the
membership of a "technicians group" to the local Admins
group and still set the user to be a member. The problem
is since it is a GPO; it only applies to the computer in
the OU. Well the groups on the computer are local and
cannot be nested with other groups. Has anyone found a
purpose for this second configuration? Additionally, any
insight on how to solve the problem without manually
configuring the desktops would be most helpful.
Thanks,
Mike