Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

GPO won't apply to local admin group.

Status
Not open for further replies.

infernon

Technical User
Jul 10, 2003
19
US
I work at a company where we've got two laptop who are always out in the field. These individuals leave the office for months at a time and have a tendency to make changes to their laptops without knowing how to correct any mistakes that might arise.
We're currently in the process of building new laptops for them and we've decided to use GPO's to lock the machines down.
Because these individuals are required to install software on their machines while they're in the field, we've added them to the local administrators group. The only things that we'd like to see locked down are their access to the network settings and ability to view certain web sites.
I've created a totally seperate OU for the two individuals and I've applied a GPO to it with read and apply permissions only for them. I've restricted the network settings and brower settings and set the GPO to run on the account and not the computer itself.
I'm finding the the browser settings are being applied and that the Network Neighborhood icon has been removed from the desktop, but they're still able to view the network properties by right clicking on the network status icon in the system tray (which they'll need to have for troubleshooting purposes). If I remove one of them from the local admin group on the machine, I'm finding that they're restricted as intended and that the nature of their membership in the local admin group is what's causing the GPO to not be applied. Does anyone have any idea how I can rectify this?
 
I assume you have thoroughly considered the GP options under User Configuration / Administrative Templates / Network / Network Connections.

If you are in a Domain setting, join the laptops to the domain and make the GPOs of the Domain apply. Configure the user profile, including applications, for the Domain logon.

Then even if the user selects at logon the local console it will not screw up the settings that you made in the Domain logon context.
 
I actually got this figured out. In my haste, I disabled instead of enabling the last option for applying the policy to the administrators group. Doh!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top