Local Group Policy Objects (GPO) apply to all users who sign onto the computer. With that said, I have a nasty little trick you can use. The file %SYSTEMROOT%\system32\GroupPolicy\User\Registry.pol contains local user policy. Change permissions on this file to deny access by the local Administrators group, as shown in the figure below. Do this only after configuring local policies. If you need to edit the policies later, simply take ownership of the file by clicking Advanced and then clicking the Owner tab.
This was first published in July 2003
Join the conversationComment
Share
Comments
Results
Contribute to the conversation