Windows 8 -- Local Admins via "Group Policy" ?

My new machine image has "Domain Admins" as
"Local Admins", but then I manually do the below
1. login to client's machine
2. open Computer Management
3. expand Local Users and Groups, then Groups
4. double click "Administrators"
5. add "Local Admin Techs" GROUP
6. save

How can I change my Domain Controller's
"Group Policy/etc" so I don't have to
manually do above step #5 ?



Following this articles, you will be able to add an Active Directory group that could have only Local Administrator access to your target clients (via GPO)....

GPO to push out local administrators across a domain

How To Use Restricted Groups

I'm sorry.....is that suitable for your needs? Probably I may misunderstood your request....



Following this articles, you will be able to add an Active Directory group that could have only Local Administrator access to your target clients (via GPO)....

GPO to push out local administrators across a domain

How To Use Restricted Groups

I'm sorry.....is that suitable for your needs? Probably I may misunderstood your request....



Or you could create a batch file for a computer policy logon script and below would be the content of the batch script:
net localgroup administrators "domainLocal Admin Techs" /add



Here is my method of doing it:
http://deployhappiness.com/clever-way-manage-administrative-rights-regular-users/

Your users will also be an admin just while they are logged in - so you don't have to worry about something using their permissions on remote machines.



The issue with restricted groups GPO is that if you change the group membership by adding a different user on a PC, the GPO will overwrite the changes. Something to consider.



Share this

Related Posts

There was an error in this gadget