MCSA/MCSE 70-290 Exam Prep: Managing and Maintaining a Microsoft Windows Server 2003 Environment (2nd Edition)
| A new Group Policy feature introduced in Windows Server 2003 is Restricted Groups. The Restricted Groups feature allows an administrator to control the membership of the local groups on workstations and member servers. Domain Controllers are not included because they don't have local groups. The administrator is able to control the membership in the group by specifying the members of the group in the GPO. Any additional members that may have been added to the group are removed during the Group Policy refresh. The administrator is also able to specify what groups the restricted group is a member of. There are two ways to apply a Restricted Groups Policy:
In Step by Step 10.3, we're going to create a new GPO and use it to assign a Restricted Groups GPO to the Workstations OU that contains our test server. To perform this exercise, you will need to create a share on your server and name it Users. Configure the permissions on the share Authenticated UsersFull Control.
By limiting membership to important local groups on your server, such as the Administrators and Power Users groups, you can reduce your security exposure by making sure that unauthorized users accounts aren't present in these groups, either accidentally or intentionally. |
Категории