Answered by:
How to Disable

-
We have couple of laptop users with local administrator privilege. on a local security auditing we find these users add other accounts as part of the local administrator. we want to disable the same . How do I create an organization wide policy to prevent users adding other accounts in Local administrator account. Thanks a lot for sharing your thoughts
Sumesh.
Question
Answers
-
you need to apply restricted groups
heres a rundown http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/
- Proposed as answer by Ethan HuaMicrosoft contingent staff, Moderator Thursday, August 06, 2015 5:26 AM
- Marked as answer by Ethan HuaMicrosoft contingent staff, Moderator Thursday, August 06, 2015 5:26 AM
All replies
-
you need to apply restricted groups
heres a rundown http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/
- Proposed as answer by Ethan HuaMicrosoft contingent staff, Moderator Thursday, August 06, 2015 5:26 AM
- Marked as answer by Ethan HuaMicrosoft contingent staff, Moderator Thursday, August 06, 2015 5:26 AM
-
Agree that you should use Group Policy Restricted Groups to explicitly set the membership of the local Administrators group.
Just add the local Administrators group by doing a right click on Restricted Groups, then add any users/groups that you would like them to be the local administrators into the "Members of this group:" list.
For more information about Group Policy Restricted Groups, please refer to this article: http://social.technet.microsoft.com/wiki/contents/articles/20402.active-directory-group-policy-restricted-groups.aspx
Hope this helps.
Regards,
Ethan Hua
Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com
-
> you need to apply restricted groupsSorry - restricting groups will not prevent anything... At best, it willreset during the next background update.If you need a secure solution, do NOT MAKE USERS LOCAL ADMINS. That said :)
Greetings/Grüße, Martin
Mal ein gutes Buch über GPOs lesen?
Good or bad GPOs? - my blog…
And if IT bothers me - coke bottle design refreshment (-: