I find using the below line within a startup script to be the best method - this example is within a domain called home and a user called Ray... NET LOCALGROUP Administrators "home\Ray" /ADD _____ From: gptalk-bounce@xxxxxxxxxxxxx [mailto:gptalk-bounce@xxxxxxxxxxxxx] On Behalf Of Auld Colin Sent: 30 August 2007 14:29 To: gptalk@xxxxxxxxxxxxx Subject: [gptalk] Restricted Groups - appending to local administrators Is there a way to *add* a member to the local administrators group on a member server using Restricted Groups? I know that, normally, a Restricted Group policy will remove any existing members and replace them with those set in the policy. But what I'd like to do is use Restricted Groups to extend the list i.e. leave the existing members as they are... Col |* This e-mail, and any attachments, is confidential and for the use of the addressee only. |* If you are not the intended recipient, please telephone +44 (0) 1506 408700 |* We do not accept legal responsibility for this e-mail or any viruses. |* All e-mails sent and received by us are monitored. |* Contracts cannot be concluded with us by e-mail. |* This message has been sent from a member of the British Energy Group (the "Group"). |* The parent company of the Group is British Energy Group plc, a company registered in Scotland, registered number 270184, and having its registered office at |* Systems House, Alba Campus, Livingston EH54 7EG