Domain user in local administrator group

O

oscarmok

If I put the domain user into their xp local administrator group, will
the gpo able to overwrite the local administrator rights?

I have users with scanner attach to their pc. I was told only power
user and higher local groups can run the scanner without any problem.
I want the user to use the scanner but still apply our gpo (like no
add/remove program; access registry etc.) All user accounts are
domain account.

Please help!!
 
B

Brian Desmond [MVP]

Hi,

The GPO will only override the user's membership if there is a restricted
group defined for local admins. If this is the case, add the user to the
restricted group in the GPO.

--
--
Brian Desmond
Windows Server MVP
(e-mail address removed)12.il.us

Http://www.briandesmond.com
 
I

Igor Fomin

All will be all right. Althoug they will be Local Administrators all the
restrictions still will be apply to them. The other hand is that they will
be able to do lots of restricted actions using other methods (command prompt
tools and so on).

You wrote that it will be enough to make them Power Users only? It's the
best decision, I think... You can not select Power Users group when you edit
Restricted Group in GPO, but you can just type "Power Users" there...
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top