Yep, just be careful, you can get into fun situations since that information has two replication channels, through GPOs and through AD replication. I have seen more than one occasion where an out of sync GPO causes a group membership to bounce back and forth between what the old GPO says and the new GPO says and in the meanwhile that membership replicating back and forth across the domain.
joe -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Phil Renouf Sent: Wednesday, May 04, 2005 9:31 AM To: [email protected] Subject: Re: [ActiveDir] How to make a user member of Built in Administrat or group You can use Restricted groups on the Built-In Administrator group? I always thought that was intended for the local groups on member servers/desktops never really thought to see if it applied to DCs as well. Phil List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
