Add Users to local admin and remote desktop group using GPO
This tutorial will show you how to use the GPO Restricted Groups to add IT support technicians into the local administrator group of all PC's the policy is applied to. Using Group Policy to add users to the local admin group is a safer and better practice than providing domain admin privileges to technicians that do not have the need or experience to be working beyond the workstation level.
1.Define Security Group
First you need to define a security group in AD users and computers. In this example I am creating a security group called IT_Tech
- Log onto a Domain Controller
- Right click Users, New->Group->Security Call it IT_Tech
- Add the proper members.
Create Group Policy.
Next you need to create a group policy or use the default Domain Policy (not recommended).
For this example I am creating a separate policy called "Local Administrators"
- Open Group Policy Management Console
- Right click your domain or OU.
- Click Create a GPO in this domain, and link it here.
- Call it "Local Administrators"
- You should see the policy in the tree now.
3. Edit the policy to contain the IT_Tech group
Here you will add the IT_Tech group to the local administrators policy and put them in the groups you wish them to use.
- Right click "Local Administrators" Policy.
- Expand Computer configuration\Policies\Windows Settings\Security Settings\Restricted Groups
- In the Right pane of Restricted Groups, Right click and hit "Add Group..."
- Type IT_Tech and hit 'OK"
- Click Add under "This group is a member of:"
- Add the "Administrators" Group.
- Add "Remote Desktop Users"
***You can use this method to add users to other groups as well***
Log on to a PC and type gpupdate /force then check the local administrators group. You should see IT_Tech in the group now.