Tech Support > Microsoft Windows > Security & Administration > Local Group Policy Deny Administrator
Local Group Policy Deny Administrator
Posted by Jonathan on January 19th, 2006


Network: Windows NT 4.0 Server SP6a
WorkStation Windows NT 4.0 WorkStation + Windows XP

Hi all.

I install a fresh windows Xp on a machine. Because I don't have Active
Directory on my network, I configured many Local Group Policy on my machine.
You know that when you configure Local Group Policy for a computer, the
policies are applied to all user even Administrator.

So I saw on the web that if you deny the Domain Admins group or a user to
read the folder C:\Windows\Systen32\GroupPolicy, the policies wont be apply.

I did that on my first XP computer and it work well, but i'm now installing
a new computer and do the same thing, but it don't work.

Do you have any idea why my Administrator (Domain Admin), even if I deny it
to read the folder C:\Windows\System32\GroupPolicy, all the policy still
apply ?

Thanks

** I flush the Administrator profile without success.
** Sorrry for my english

Posted by Steven L Umbach on January 20th, 2006


Try giving also giving "administrators" deny permission for that
lder. -- Steve


"Jonathan" <Jonathan@discussions.microsoft.com> wrote in message
news:A930CEDD-8189-4185-8592-A27A3D3CF04B@microsoft.com...