Using Restricted Groups to grant local admistrator to laptop

Home Forums Microsoft Networking and Management Services GPO Using Restricted Groups to grant local admistrator to laptop

This topic contains 1 reply, has 2 voices, and was last updated by Avatar gforceindustries 9 years ago.

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • Avatar
    noway
    Member
    #153846

    guys,
    i need your help..

    i know to use the Restricted Groups, however, i need to know how i can allow laptop users to have local admin right with giveing the ablity to remove any user from the local administrators group.

    this is what i did:
    i have Restricted the local administrators to have the following:
    domaindomain admin
    domainlaptop users
    administrator

    now, every user in the group laptop users will have a full access on other laptops. what i want is the Restricted the local administrators group in this way:
    domaindomain admin
    domainuser
    administrator

    and i don’t want the user to have any rights to delete the reset of the administrator group..

    any help…

    #344838

    Re: Using Restricted Groups to grant local admistrator to laptop

    If a user is a local administrator, then they will have the necessary permissions to remove other users from the administrators group.

    If a user can’t be trusted with these permissions, then don’t make them a local admin.

    If you’re giving them admin rights because of an application experiencing compatibility issues, then you should contact the application vendor to fix their product.

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.