Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

Restricted Groups problem - modifying too broadly

$
0
0

Hello,

I have a problem with Restricted Groups GPO setting. I have created a GPO setting for an OU of computers in the domain. Even though I understood from several posts that if I define the GPO in the "This group is a member of" setting, this would add the group, this does not happen - the other users have been wiped and only the group added. OK, I can manage this and is not such a problem.

Here is the problem: I have been modifying the local Administrators group. The Administrators group now also gets wiped on servers, which means that the only user left in there is the local Administrator account, effectively kicking the domain admin out of the system! Of course the above policy does not apply to the servers so that the Domain Admin is not added and I am getting locked out of domain servers.

What am I missing, what am I doing wrong and how can I get rid of the Restricted Groups setting altogether without it messing up all the rights again?


Viewing all articles
Browse latest Browse all 19997

Trending Articles