Local administrator seems to be enabled for all users


environment:
server 08 r2

client: 
windows 7

ou stucture:

employees (there policy attached ou)
  banner users
  non-banner users


here i've done step-by-step: 

1. employees ou - right click, new group
2. group name: wksadmins, group scope: universal, group type: security
      -added user want local admin , user
3. gpmanagementeditor  - edit policy attached employees ou
4. user configuation -> preferences -> control panel settings -> local users , group -> new local group
5. action: update, group name: administrators (built-in), (o) add current user, added wksadmins group, ok


the user want local admin (and member of wksadmins group) in banner users ou, , user have local admin rights.  now, have user in non-banner users ou.  this user not member of wksadmins group.  i log in user , when go start > run > msconfig, prompt username , password, if enter users credentials , hit enter, msconfig opens.  now designed in windows 7 specifically, b/c remember if limited user in xp, not pull system configuration utility.  however, user tried: start > run > rsop.msc , said "access denied" made me feel little better.  however, user, went start > run > compmgmt.msc > groups , user member of administrators group.  please note first time user account has ever been logged in.  so, know if did wrong in preference configuration?  how steps look? 

i wish there easy way upload screenshot.  

thanks in advance



not sure how adding currnet user built-in administrators group in step 5... think know answer...

in step 5... add wksadmins group administrators (built-in) group. sure tick "remove users" , "remove groups"
step 6. add local group entry administrators (built-in) group , add current users. in filter options configuration to not apply if user account is member of non-banner users ou.

i have written articles local admin group changes using group policy preferences might help... http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/


alan burchill @alanburchill http://www.grouppolicy.biz


Windows Server  >  Group Policy



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file