As already everyone knows, using "Restricted Groups" GPO facility in a Windows 2003 Server environment brings us a lot of advantages. Until now I haven't figure out a simple way of achieving following : use Restricted Groups, but in same time restrict specific user to be local administrator only on one workstation. If it's deployed a global security group to an entire environment, then all users from that group will be local administrators on all machines from that OU. How can we restrict users from that designated global security group to be local administrators only to their single laptop/desktop ?
No announcement yet.
Using "Restricted Groups" to logon as administrator to a single workstation?