Restricting Group Membership update


hi

in company based on necessity provide admin privilege users adding user account local administrators group. found security flaw in that. whoever getting admin privilege adding team members local administrators group without passing information have full privilege on pc. workaround restricted them on accessing local users , groups console. still there lot of other ways including commands. 

is there way restrict this? not want misusing admin privilege.


shanif salim

hi shanif,
alternatively, use group policy preferences secure local administrator groups, here article has same request yours, please take , have try following it:
how use group policy preferences secure local administrator groups
http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/
please note: since web site not hosted microsoft, link may change without notice. microsoft not guarantee accuracy of information.

regards,
wendy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group