Hello Chris (Stolle).,
Thank you for your reply.
Based on the information above,
***Group Policy Preferences -> Computer Configuration -> Preferences -> Control Panel Settings -> Local Users and Groups -> New -> Local Group -> Action: Update -> Group Name: Administrators (built-in) -> Members: Add... (pick Sally / check name / return) -> Action: Remove from this group -> OK -> OK.***Because you configured the computer configurations (not the user configurations), you should link to OU with Computer objects.
Hi Daisy or anyone else. Just to clarify. Are you saying that I should just link my EUC: Remove Local Admin rights from users to the "Computers" OU like this?
A: Yes
Or do I need to add the individual users Computers to the OU under the security filtering? I currently do not have any of the users computers listed under the security filtering. I only have all their username I want removed from the Local Admin group within the policy I pasted in my original post.
**A: For "security filtering", we should keep the default "Authenticated Users".**Since I only have the username within this policy should I move my policy to the OU > Location > Users? No
Or should I keep the Policy in the Computers OU for the location and add the individual users computers? You should link to OU with Computer objects.
If there is any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou