local security group into local Administrator group

local security group into local Administrator group

Post by jeffrey_hi » Sun, 04 Jul 2004 07:20:37


Would like to use Restricted Groups to standardize the local
Administrator group as much as possible. However, on SOME PCs I have
to have non-standard domain users with Administrative privileges.

I THOUGHT I could get around the "wipe and replace" behavior of
Restricted Groups by having it add a local security group to the local
Administrators group (add the local group but not specify the
members). It LOOKS like it is working. The local group is in the list
of Administrators in the GUI and in "net localgroup Administrators"
however the domain users contained in the local group cannot perform
administrative functions.

What am I missing?
Is there a better way to get some flexibility of Administrators on a
case by case basis?
 
 
 

local security group into local Administrator group

Post by Roger Abel » Sun, 04 Jul 2004 16:20:29

Evidently some code has a bug as it is not permitted for
machine local groups to nest within other machine local
groups.

--
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4) MCDBA

 
 
 

local security group into local Administrator group

Post by Eric Chamb » Thu, 08 Jul 2004 11:15:08

You can't add machine local groups, but you can create a Restricted Group
policy for a domain local group and add your machine local Administrators
group to the "members of " section of the policy. The domain group is then
added to the Administrators group.


--
Eric Chamberlain, CISSP
 
 
 

local security group into local Administrator group

Post by Roger Abel » Thu, 08 Jul 2004 11:45:04

Without third-party extensions you can only place
machines within the scope of a GPO that delivers
a Restricted Group definition for a machine local
group if all of those in scope machines are to have
identical membership in the group that is restricted.

--
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4) MCDBA