Restricted groups are a little known option in an Active Directory Domain. They control local group membership on your active directory clients. In this video, I add a domain group to a local group without going to each and every local machine using group policy. This allows me to create membership for a specific group of people to a specific group on a specific group of computers. It’s a great situation where I can make local admins or backup operators on a regional sect of computers. This feature is available onactive directory domains runningĀ Microsoft windows Server 2000, 2003, 2008. The client operating systems may include 2000, XP, Vista or 7.