Group Policy Question??

in Off-Topic
I need to search all our workstations for any employee who is in the Local Administrators Group and if they are to take them out and move them to the Power Users Group. Can this be done using GPP?
Comments
-
pham0329 Member Posts: 556
I know you can add users to the local admin via gpo using the restricted groups setting, but I don't think you can remove specific users. Your best bet would probably be a startup script. -
billybob01 Member Posts: 504
I know you can add users to the local admin via gpo using the restricted groups setting, but I don't think you can remove specific users. Your best bet would probably be a startup script.
Yes, you can add or remove users using Group Policy Preferences. I am looking into wether you can use an LDAP query with GPP to search all workstations and if a user is a memeber of the Local Admin group to remove them and add them to the Power users group. -
pham0329 Member Posts: 556
Ah, sorry, misread the post. I still think a startup script is the best option. -
-Foxer- Member Posts: 151
You could probably do it relatively easy with powershell. That's what I would look into. -
blargoe Member Posts: 4,174 ■■■■■■■■■□
I know you can add users to the local admin via gpo using the restricted groups setting, but I don't think you can remove specific users. Your best bet would probably be a startup script.IT guy since 12/00
Recent: 11/2019 - RHCSA (RHEL 7); 2/2019 - Updated VCP to 6.5 (just a few days before VMware discontinued the re-cert policy...)
Working on: RHCE/Ansible
Future: Probably continued Red Hat Immersion, Possibly VCAP Design, or maybe a completely different path. Depends on job demands...