Hi, I'm looking for a way to force computers on our domain to keep domain admins in the local administrators group. Unfortunately, restricted groups doesn't quite do what I need, because our company has a policy of making each user the local administrator on their own laptop (I know, I know, but we've found it solves more problems than it creates for our very mobile user base, especially when they work at client sites). Unfortunately, some of our users like to remove domain admins from the local Administrators group. Does anyone know of a way to require domain admins be a member of the local Administrators group and still allow individual users to be local admins on their own machines as well? Thanks, John