Hello!
We have a Windows 2012R2 AD DS domain.
For security compliance reasons, on about 20 web servers, we need to set particular NTFS level permissions to:
"C:\Windows\System32\cmd.exe"
So I decided, why not apply this via GPO.
but I'm quickly realizing that I'm unable to set "<hostname>\Administrators" group (which is inherited by default btw) when going through the "Add File" process in:
Computer Configuration - Policies - Windows Settings - Security Settings - File System
I'm running GPMC from a member server and of course the only option I have is to add the local admins account for this paritcular host. We don't want that on 20+ web servers that I'll apply this GPO to!
Anyone know how to add this? Is it possible?
Please don't ask question to the 'why'. I just want to explicitly define a few permissions (remove inheritance) and push this out to all web servers.
thanks!