|
Posted by Roger Abell [MVP] on October 12, 2007, 10:27 am
Please log in for more thread options
It would work if your DAs are well behaved (or should I say
threatened with effects flowing from misbehavior).
If you used a restricted group definition in a GPO on which
only the EAs had a grant to modify the GPO settings, then the
DAs would have to go out of their way to either override that
GPO with a higher priority GPO or alter the permissions on
that GPO and then alter the restricted group def in it.
> whats the best way of restricting membership of the dom ads group?.
> ideally i would like just the enterprise admins group to be allowed to
> change membership of the DA group.
>
> has anybdy actually done this using restricted group? and does it
> work ?
>
> dave
>
|