AdminCount=1 and Local Administrators


  • Hello,

    We have all domain users added to Administrators restricted group by GPO so all users  have local admin rights on all client machines. This also sets the "admincount=1" value on the members of this group. This means they all become members of a protected group and for example Send-As or any other rights granted manually or by Exchange get deleted every hour or so. Is there any workaround to keep all users of the domain on all machines as local admins AND fixing the "admincount" issue?

    Thank you! 

    Tuesday, March 21, 2017 8:40 AM