On 5/3/05, Jorge de Almeida Pinto <[EMAIL PROTECTED]> wrote: > FIRST: > You can use restricted groups in a GPO. > However in that is in the forest root domain then members of the builtin > administrators have control over the enterprise administrators group.
You can use Restricted groups on the Built-In Administrator group? I always thought that was intended for the local groups on member servers/desktops never really thought to see if it applied to DCs as well. Phil List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
