2008 "restricted groups" of the R2 AD Group Policy
1. First make GPO editing for an OU.
Computer configuration-policies-Windows Settings-Security Settings-restricted groups
For example, limit the administrators group to two members, administrator and manyour
2. Log in to the adtest-pc computer in the experiment, and you can see the members of the original administrators group
3. After the group policy is forcibly refreshed, you will find that the members of the administrators group have changed.
4. Once again, we log in to the adtest-pc computer with the administrator account and add manyou1 users to the administrators group. Then log in to the adtest-pc computer with manyou1, and you will find that manyou1 appears in the administrators group and has administrator privileges.
5. If the group policy is refreshed at this time, you will find that the manyou1 account will be removed from the administrators group, thus ensuring the security of the computer.