Hi Alberto, Use the restricted groups feature in a GPO.... For the group ADMINISTRATORS define/dictate which groups/users MUST/SHOULD (e.g. Domain Admins, and local administrator) be in the group ADMINISTRATORS. Everyone else not defined will not be listed and if defined prior to the configuration of the GPO will be kicked out jorge Met vriendelijke groeten / Kind regards, Ing. Jorge de Almeida Pinto Senior Infrastructure Consultant MVP Windows Server - Directory Services LogicaCMG Nederland B.V. (BU RTINC Eindhoven) ( Tel : +31-(0)40-29.57.777 ( Mobile : +31-(0)6-26.26.62.80 * E-mail : <see sender address>
________________________________ From: [EMAIL PROTECTED] on behalf of Alberto Oviedo Sent: Wed 2006-09-20 14:57 To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Assign User rights overs computers with AD Hello. My name is Alberto, I'm from Nicaragua In our company the support team has granted every user administrator rights over their workstation, We recently migrated to Windows 2003 AD and I want to revoke the privileges tha users have on their computers. Can I do this through AD? It's around 300 users and I don't want to visit every single one of them. Thanks for your help. This e-mail and any attachment is for authorised use by the intended recipient(s) only. It may contain proprietary material, confidential information and/or be subject to legal privilege. It should not be copied, disclosed to, retained or used by, any other party. If you are not an intended recipient then please promptly delete this e-mail and any attachment and all copies and inform the sender. Thank you.
<<winmail.dat>>