Jump to content

GPO restrict user access to mmc snap-ins


Recommended Posts

Hello everyone, could somebody help me with this issue that i have for school please ?

Windows Server 2012

Client : Windows 10 Enterprise

 

The request sais "the OU delegated admins must have access to the following snap-ins consoles :

1.AD UC

2.Group Policy Management

3.Group Policy Management Editor

4.Administrative Templates (Users)

5.Administrative Templates (Computers)

So i installed the RSAT tools on the client workstation, set the 2 GPO on the server :

User Configuration\Administrative Templates\Windows Components\Microsoft Management Console\Restrict user access to explicitly permited list of snap-ins

and

User Configuration\Administrative Templates\Windows Components\Microsoft Management Console\Restricted/Permited snap-ins

 

then set the permissions, and now, the delegated local admin can add the first three snap-ins in his local console, can create users, groups, he can create and link GPO's, but noway nohow I cannot add the last two snaps in the console (Administrative Templates Users/Computers)...

What am i doing wrong ? Any suggestions are welcomed...

Thank you !

Link to comment
Share on other sites

  • 2 years later...

I know this is unrelated to the topic of your entry, but sometime ago I found a very similar website to this one (it was even about the same topic!), but it was laggy as hell, it reminded me of my very old personal website.
Fortunately on my recent website I didn't got any issues as I decided to change my hosting provider to Truxgo and until today I it's working flawlessly.

Link to comment
Share on other sites

  • 2 months later...

Hello ChrisMtl,

 

It is possible to restrict access to MMC snap-ins using the Group Policy settings. You can follow the below steps to restrict user access to mmc snap-ins.

 

  1. Firstly, start Active Directory Users and Computers snap-in (Start Programs > Administrative Tools > Active Directory Users > Computers)
  2. Now, right-click on the domain or OU with the Group Policy set and select its Properties.
  3. Then, select the Group Policies tab.
  4. Choose the Group Policy you wish to change and click on Edit.
  5. Now, move to User Configuration > Administrative Templates > Windows Components > Microsoft Management Console.
  6. Double click on the 'Restrict Users to the explicitly permitted list of snap-ins.'
  7. Please set it to Enabled or Disabled type.
  8. Now, you can move the "Restricted/Permitted snap-ins" and enable or disable specific snap-ins of your choice.

 

If "Restrict Users to the explicitly permitted list of snap-ins" is set to Disable state or Not yet Configured, then the snap-ins are available unless they are explicitly set to "Disabled" form in the "Restricted/Permitted snap-ins" folder.

 

Thus, If the "Restrict Users to the explicitly permitted list of snap-ins" is set to Enabled, then no snap-ins are available unless the snap-in is explicitly set to "Enabled."

 

I hope the above fix will help you to resolve "GPO restrict user access to mmc snap-ins" issue.

 

-------------------------

Regards,
Rex M

 

 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy