local admin via gpo

Soldato
Joined
15 Sep 2009
Posts
2,895
Location
Manchester
Add the computer into the security filtering and take out all computers in the GPO. Also filter the user component to a security group and only filter it on that security group, should work fine.
 

GDL

GDL

Associate
Joined
10 Sep 2014
Posts
430
Location
UK
Add the computer into the security filtering and take out all computers in the GPO. Also filter the user component to a security group and only filter it on that security group, should work fine.
+1 this.
Restrictive groups with a filtered GPO applying to that one machine.
 
Soldato
Joined
1 Apr 2014
Posts
18,631
Location
Aberdeen
It's a bit more work but a more useful long-term solution is to create a group in AD called something like Local_Admin_PCName, then add that to the PCName\Administrators local group. This makes it easy to manage centrally and allows more than one local admin. For instance, most PCs might have a group called Tech_Support_Staff as a member.
 
Soldato
Joined
18 Oct 2002
Posts
8,121
Location
The Land of Roundabouts
It's a bit more work but a more useful long-term solution is to create a group in AD called something like Local_Admin_PCName, then add that to the PCName\Administrators local group. This makes it easy to manage centrally and allows more than one local admin. For instance, most PCs might have a group called Tech_Support_Staff as a member.


Just to build on this
I was gonna write a quick guide but this is far better and i couldnt quite get my wording legible! :)
http://www.pwrusr.com/system-administration/how-to-setup-per-computer-local-admins-on-a-domain

But you may want to reconsider.
With the whole poop show that is cyber-essentials, gdpr etc we cant just give users admin access, privileged accounts now have to be a separate account so we use LAPS that dynamically changes the local admin password so we give that out to allow them to do what they need then expire the password.
 
Back
Top Bottom