How to remove the permission to delete a GPO for Domain Admins


hi there,

i able set deny delete statement in group policies domain admins not able delete them. when try in environment using gpmc domain admin account able remove policy. environment windows 2008 r2

the aim prevent accidental deletion of few key policies allowing small group access. know limitation security here - want reduce possibility of accidents rather secure policies against domain admins.

thanks in advance,

goldstien


hello,

here go:

can use "active directory users , computers" snap-in.
ensure have "view - advanced features" enabled.
goto "system".
browse gpo.

edit properties:

you can in gpmc.

add "everyone" , deny "delete" , "delete subtree".


mvp group policy - mythen, insiderinfos und troubleshooting zum thema gpos: let's go, use gpo!



Windows Server  >  Group Policy



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client