AGHHHHHHHHH.
Just tried Restrictive Groups again and it still does not apply to the user, ran gpresult and my Group Policy is not getting applied.
Apply it to the computer! Forget about the user.
Restrictive groups will remove EVERYONE from the local admin group and allow you to add in the Domain Admin Group, The other Admin Group and INSTEAD OF ADDING A PARTICULAR USER ADD A GROUP THAT THAT USER BELONGS TO.
I don't understand where I am failing to get this point across but I have reached the end of my frustration level.
If you do manage to resolve this issue in the backwards manner you are determined to do it in, you will not have corrected the problem, only the symptom.
By creating a domain group for users allowed to install software and making that group a member of the local admins group on the local PCs you will be able to restrict those users int he future if need be by removing them from the group. If they had logged on to 10 machines it would not matter because their user ID is not in the local group, only the Global Group is and if they are no longer a member of that group, then their access has been restricted locally.
I hope you find this post helpful.
Regards,
Mark
Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.