Modifying local GPOs for non-administrator user accounts

2025-05-14Last updated

By default, non-administrator user accounts have restricted access to Streamvault™ appliance features. To customize their permissions, you can modify the local group policy objects (GPOs) for the Non-Administrators group through the Microsoft Management Console.

Procedure

  1. From the Windows Start menu, select Run, then type mmc.exe, and click OK.
    The Microsoft Management Console window opens.
  2. In the left pane, click File > Add/Remove Snap-in .
    The Add or Remove Snap-ins dialog box opens.
  3. In the Available snap-ins section, select Group Policy Object Editor and click Add.
    Add or Remove Snap-ins window - Adding the Group Policy Object Editor snap-in.
  4. In the Group Policy Object wizard, click Browse.
  5. In the Browse for a Group Policy Object dialog box, click the Users tab, select the Non-Administrators group for which a local GPO exists, and click OK.
    Browse for a Group Policy Object dialog box showing the Non-Administrators group selected.
  6. In the Select Group Policy Object dialog box, click Finish.
  7. The Add or Remove Snap-ins dialog box, click OK.
  8. In the Microsoft Management Console window, go to Console root > Local Computer\Non-Administrators Policy > User Configuration > Administrative Templates > Streamvault > <hardening profile> ,
    where <hardening profile> represents one of the four predefined hardening profiles: CIS Benchmark Level 1, CIS Benchmark Level 2, Genetec™, and Microsoft Security Baseline.
    All the GPOs that are configured for non-administrator accounts are listed in the selected hardening profile.
    Note:
    A GPO is configured if its state is Enabled or Disabled. A GPO with a state of Not configured is not controlled by Streamvault.
    Microsoft Management Console showing the GPOs in the Genetec folder that are set for the Non-Administrators group.
  9. Double click the individual GPOs to view or edit them.