elTorito wrote: » Edit: I wouldn't recommend making anyone local administrator, especially not managers
elTorito wrote: » The restricted groups policy is a Computer Configuration setting. As such, you cannot scope it to a user. To achieve what you have in mind, create a GPO (or use an existing GPO), configure the DOMAIN\Managers security group to be a Member Of of "Administrators" in the Restricted Groups node, then scope the GPO to the OU that contains your domain computers. The result will be that the Managers group is added to the local administrators group on top of existing memberships, such as .\administrator and Domain Admins.