Restricting GPO snap-ins and filtering the policy

M

Mike Towan

Hi all, I need a reality check on my logic here before I apply it.

I want to explicitly deny the ability to add certain snap-ins to GPO and
also want to prevent most MMC users (PC Tech Group) from entering author
mode, however I want DomainAdmins to have full access. If I apply this
policy at the root of the domain, then deny read/apply access to the Domain
Admins group, will this work?

Thanks in advance,

Mike
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top