Local administrator seems to be enabled for all users
environment:
server 08 r2
client:
windows 7
ou stucture:
employees (there policy attached ou)
banner users
non-banner users
here i've done step-by-step:
1. employees ou - right click, new group
2. group name: wksadmins, group scope: universal, group type: security
-added user want local admin , user
3. gpmanagementeditor - edit policy attached employees ou
4. user configuation -> preferences -> control panel settings -> local users , group -> new local group
5. action: update, group name: administrators (built-in), (o) add current user, added wksadmins group, ok
the user want local admin (and member of wksadmins group) in banner users ou, , user have local admin rights. now, have user in non-banner users ou. this user not member of wksadmins group. i log in user , when go start > run > msconfig, prompt username , password, if enter users credentials , hit enter, msconfig opens. now designed in windows 7 specifically, b/c remember if limited user in xp, not pull system configuration utility. however, user tried: start > run > rsop.msc , said "access denied" made me feel little better. however, user, went start > run > compmgmt.msc > groups , user member of administrators group. please note first time user account has ever been logged in. so, know if did wrong in preference configuration? how steps look?
i wish there easy way upload screenshot.
thanks in advance
not sure how adding currnet user built-in administrators group in step 5... think know answer...
in step 5... add wksadmins group administrators (built-in) group. sure tick "remove users" , "remove groups"
step 6. add local group entry administrators (built-in) group , add current users. in filter options configuration to not apply if user account is member of non-banner users ou.
i have written articles local admin group changes using group policy preferences might help... http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/
alan burchill @alanburchill http://www.grouppolicy.biz
in step 5... add wksadmins group administrators (built-in) group. sure tick "remove users" , "remove groups"
step 6. add local group entry administrators (built-in) group , add current users. in filter options configuration to not apply if user account is member of non-banner users ou.
i have written articles local admin group changes using group policy preferences might help... http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/
alan burchill @alanburchill http://www.grouppolicy.biz
Windows Server > Group Policy
Comments
Post a Comment