Hi Nation members-
I'm having a bit of a problem trying to conceptualize this, and maybe one of you can help me. It was decried from on high that we will not be granting local admin privileges unless you are a member of a specific AD group.
I am using a small dseditgroup script to apply admin privileges on the machines, that part works.
The issue I am facing is I have some people who had the local administrator rights from the get-go being in violation of that policy, so I will need to make a script to check if they are a member of said group, then remove their admin privileges until they fill the proper forms and get added to the group.
I have a good idea of what I want to do, but I can't figure it out :(
Thanks