Use group policy to controlt user access


  • Hi

    Is it possible to use AD group policy to control user access?

    For example, two access group, one is admin with full privilege, the other group only has the permission to RDP and install software on the server. Can this be achieved by applying group policy?

    If possible please provide a bit more details on how this can be achieved?

    Wednesday, June 10, 2015 12:43 AM


  • Hello Kelly,

    Thanks for the post, I guess you are talking about the restricted group feature in the group policy.

    The feature can make you add user accounts to groups on client machines that are in the scope of the policy.

    In your case, you can use this to add the users as local administrator via group policy instead of adding them in each client manually.

    You can check the below link for more details:

    Hope it helps.

    Best Regards,


    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact

    Thursday, June 11, 2015 8:12 AM