dave0212 wrote: Yes if you do it the opposite way to how I have done it. If you create a group called LocalAdmins in AD and add your user account Then in the default Domain Policy or a new one Create a restricted group for YOURDOMAIN\LocalAdmins and in the "This group is a member of" and type Administrators This should leave your current local admins intact I do it the other way round to prevent users installing applications etc