Yes,
Restricted Groups... Scope the GPO to the Location in AD in which the servers reside ( Usually a Servers OU accordingly). They will be local administrators on those servers but not a Domain Admin. Without knowing much else about the situation, Id even say that is way too much rights, what is the functions that these non-domain admin group members need to accomplish? Z Edward Ziots CISSP,MCSA,MCP+I,Security +,Network +,CCA Network Engineer Lifespan Organization 401-639-3505 [email protected] From: Graeme Carstairs [mailto:[email protected]] Sent: Thursday, June 10, 2010 9:48 AM To: NT System Admin Issues Subject: Heres a weird one - customer wants to give domain admin rights to non domain admin group members. I have been asked by a customer if on their 2003 AD domain it is possible for someone to have admin rights to the servers and not be a member of domain admins. and local admin groups on member servers. Any one know if it can be done Graeme -- Good news everyone, you have just received and e-mail from me! ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
