Restricted Groups

S

Srinivas Acharya

Hi,
I have added the domain user to local administrator group
of all the PCs coming under one OU with the help of
restricted groups. but now I have moved that PC from that
OU. But still that user is in the administrator group of
those PCs. Why still that user is having admin previleges
even though that user is no more in that OU. Please any of
you could address this issue?.
Regards,
Srinivas Acharya
 
S

Steven L Umbach

Not all security policy settings are removed when a computer is remove form the scope
of the policy. Restricted groups is one of them, and file/registry permissions is
another. Settings under administrative templates are usually changed to reflect the
Local Group Policy setting if the new location has an undefined setting in the
PO. --- Steve
 
P

ptwilliams

This is called registry tattooing!! Have a look at this great resource from
*the* GPO man:
-- http://207.104.31.209/gpoguy/FAQs/tattoo.htm

--

Paul Williams
_________________________________________
http://www.msresource.net


Join us in our new forums!
http://forums.msresource.net
_________________________________________


Not all security policy settings are removed when a computer is remove form
the scope
of the policy. Restricted groups is one of them, and file/registry
permissions is
another. Settings under administrative templates are usually changed to
reflect the
Local Group Policy setting if the new location has an undefined setting in
the
PO. --- Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

Restricted groups 1
Regarding OU 9
Administering OUs 5
Planning for OU 2
Problem with restricted groups 3
problem with restricted users 1
Restricted Groups 3
Restricted Group 1

Top