GP editor question

  • Thread starter Thread starter roger
  • Start date Start date
R

roger

I think i asked this question, but i don't think ive gotten it fixed yet.

xp pro SP2 installed. Single computer, no domain.
Goal: Prevent any user except one specific administrator from changing any
settings within secpol. Is this possible? if so, how?
 
Only administrators can open and use Local Security Policy. While
realistically you can not restrict a knowledgeable administrator what you
could try is to give users/group deny permissions to the
\Windows\system32\group policy\machine folder and that user or user in the
group will not be able to open Local Security Policy of local Group Policy
unless they figure it out and remove the deny permissions. --- Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top