Restricted Groups Issue

L

Lee Messenger

Hi,

I am using the Restricted Groups feature to give my helpdesk personnel admin
access to all the users PC for support purposes.

I also have some users that require admin access to their PC as well. If I
make a group for these users then add them to the restricted groups policy,
these users will be admins on all the PC's in the OU is linked to.

This means these users will be able to get to the c: drive of all the PC's
in the OU.

Is there any way of stopping local administrators from browsing to other
computers c$ shares ?

TIA

LM
 
S

Steven L Umbach

For those users add their domain users account individualy to the local
administrator account on their computer only. --- Steve
 
L

Lee Messenger

Steven,

If I do that, the restricted group policy will over-write what I do
manually.

For example, if I make my helpdesk group members of the local administrators
group using a GPO, if I then modify the local admin group on the PC, the
GPO settings will remove the manual modifications on the next reboot.

Regards,
 
S

Steven L Umbach

Good point. You may need to move those computers into an OU that does not
have a restricted groups setting and manually configure the local
administrator account with both the user and help desk group. You could do
it remotely via Computer Management. -- Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top