You will have to use "Domain Users". But, should you? Big question that opens up a lot of unwanted side effects. Your goal is to "make sure all users are local admins on THEIR PCs". With this approach, you will get "make sure all users are local admins on ANY PC they log into". Are you cool with that? You answer the question. Sincerely,
Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon ________________________________ From: [EMAIL PROTECTED] on behalf of Rimmerman, Russ Sent: Fri 10/28/2005 8:37 AM To: [email protected] Subject: [ActiveDir] Restricted Groups question Is there any way to add "Authenticated Users" built-in group to the local administrator group on every PC using restricted groups GPO? Basically I want an easy way to make sure all users are local admins on their PCs without creating a custom group. Should I just use xxx\domain users instead? ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This e-mail is confidential, may contain proprietary information of the Cooper Cameron Corporation and its operating Divisions and may be confidential or privileged. This e-mail should be read, copied, disseminated and/or used only by the addressee. If you have received this message in error please delete it, together with any attachments, from your system. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
