We have a laptop environment where the user of the laptop MUST be a member of the LAPTOP/Administrators. Since the laptop is a computer in a Domain, the user then becomes a member of the DOMAIN/Domain Admins group. This, of course, is not acceptable in our environment. I remove the DOMAIN/Domain Admins group from LAPTOP/Administrators group, but this doesn’t solve the problem. My question is how can a domain user be a member of the LAPTOP/Administrator group without having Domain Admin rights?