none
GPO Restricted Group RRS feed

  • Question

  • here is my situation - I have created a top level OU for computers where I have a GPO to control group membership in the Local Admins Group.  Example:  only Desktop Admins is member of the local Administrator's group of the workstation.  This part is working fine as it removes any other user/group that is added to the Local Admininstrators group of the workstation.  I also created a subOU (example: devcomputers) where I need to not only add the Desktop Admins group but also the DEV Admins Groups.  this also works fine as it removes any other user/group from the local Administrators group.  I also need to create a subOU under this top level OU where the Desktop Admins group is added to local Administrator's group but also append other users/group to the local administrators group.  this is where I have the problem.  it removes the Desktop Admins group from the local administrators group except for the administrator's local account.  How do I correct this?
    Wednesday, June 12, 2019 1:37 PM