GPO for users with admin rights

Archived from groups: microsoft.public.win2000.group_policy (More info?)

Hi,
Will GPO;s that enforce lockdowns apply to users that have admin
rights to the workstations ? do the admin rights override the group
policy?
1 answer Last reply
More about users admin rights
  1. Archived from groups: microsoft.public.win2000.group_policy (More info?)

    Kiosk,

    Absolutely, to your first question. Absolutely not, to your second
    question.

    The key here is to use Security Group filtering. The security group, by
    default, that is given both the READ and APPLY GROUP POLICIES is the
    Authenticated Users group. This Group does not discriminate!

    So, what you would do is one of two things: add the Domain Admins group ( or
    whatever group you wanted ) to the security tab of this GPO and give it the
    explicit DENY to the APPLY GROUP POLICY right -OR- create a security group
    that is populated with the user account objects that you need, add this
    security group to the security tab of the GPO, make sure to give this group
    the READ and APPLY GROUP POLICY rights and then remove the Authenticated
    Users.

    HTH,

    Cary

    "Kiosk" <jramos@netcom.com> wrote in message
    news:b1vgk0paofv1i14oiv9g6srmcilh0sf700@4ax.com...
    >
    > Hi,
    > Will GPO;s that enforce lockdowns apply to users that have admin
    > rights to the workstations ? do the admin rights override the group
    > policy?
Ask a new question

Read More

Policy Workstations Microsoft Windows