Amen, brother!
When I first started here last year we had to do a major cleanup of Admin-related groups on our domain and still have to cleanup some local workstation groups that are controlled via GPOs. We just recently spun a portion of our users off into their own domain and we used Restricted Groups/Delegation from the get-go. Don Guyer Systems Engineer - Information Services Prudential, Fox & Roach/Trident Group 431 W. Lancaster Avenue Devon, PA 19333 Direct: (610) 993-3299 Fax: (610) 650-5306 don.gu...@prufoxroach.com From: David Lum [mailto:david....@nwea.org] Sent: Wednesday, April 22, 2009 1:57 PM To: NT System Admin Issues Subject: Restricted groups, where have you been.... ...all my life! We are just getting to use this feature and it's DA BOMB! Being able to add users to local groups w/out affecting the existing memberships is awesome! We are narrowing down how many Domain Admins we have and this feature is *hugely* helpful in delegating to non domain admins. David Lum // SYSTEMS ENGINEER NORTHWEST EVALUATION ASSOCIATION (Desk) 971.222.1025 // (Cell) 503.267.9764 ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~