Local user deny in Active Diretory

Anonymous
2021-06-18T04:59:33.303+00:00

Hello.
i find docs (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-h--securing-local-administrator-accounts-and-groups)
i want to apply that.
but i have 100 more local account.
How can I organize it efficiently?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,956 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2021-06-18T06:19:51.797+00:00

    Hi,
    Based on my research, we don't need to do this for all he local accounts.
    We did this to protect the local administrator account.

    Or if you do need to do this, you can add the local accounts into a group.
    Then you can use the GPO to deny the rights to the local group.
    106922-6184.jpg

    Best Regards,

    0 comments No comments

  2. Anonymous
    2021-06-18T07:53:59.583+00:00

    can i register group "Administrator"?
    i register "Administrator" but system occur Error
    So i do not there ㅠ.ㅠ


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.