Excluding Admin from group policy

R

Randy

How can i prevent a restricted user account from
accessing features such as the control panel, run command
etc. but still allowing the administrator access to these
features. i tried using group policy but it restricted
the admin account too. Im running w2k with workgroup
setting. Im new to this so i dont know that much about
what im doing.

Thx.
 
S

Sabin Nair[MSFT]

Hi Randy,

There are multiple ways of applying a policy:

Ex: you could add a security group of computers or users and apply the
policy to that group. You would do this from Properties -> Security tab

You could also just apply the polciy to the entire user or computer group by
giving "read" and "apply" rights to authenticated users.

Now, an admin is also an authenticated user and hence the polices will apply
to them. So, you need to explicitly deny them from that policy (select deny
for admins).

--
Thanks
Sabin Nair M.S(Computer Engg.), MCSE, MCSA
Directory Services Team
Microsoft Corp.

"Please do not send e-mail directly to this alias.
This alias is for newsgroup purposes only."
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top