Local Administrator & Local GPO on a workgroup computer

D

DCA

We want to implement a GPO but not have it affect the local administrator
account on each machine.

We're looking for an easier way to engage the GPO w/out having to resort to
copy the registry.pol file everytime we need to make a small change.
Currently the method is cumbersome at best and leaves a lot of room for
error. I recalled seeing a post about denying read access to the local
admin account/group but can't seem find again. I'm not sure if it works
only in domain environment. We only have Win2000 and no WinXP machines.
Thanks in advance.
 
D

DCA

Thanks for the quick reply. The only thing that should added is to deny
both read & execute permissions as well. Otherwise, thanks again...really
appreciate it.
 
J

jim

Can't you go to the properties of the domin
policy>security tab and remove the check for apply group
policy, or deny apply group policy, to the admistrators
group?


-----Original Message-----
293655 HOW TO: Apply Local Policies to all Users Except Administrators on
http://support.microsoft.com/?id=293655

--
Richard McCall [MSFT]

"This posting is provided "AS IS" with no warranties, and confers no
rights."
DCA said:
Thanks for the quick reply. The only thing that should added is to deny
both read & execute permissions as well. Otherwise, thanks again...really
appreciate it.


the local
administrator
w/out having to
resort leaves a lot of room
for access to the
local not sure if it
works and no WinXP
machines.

.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top