"Clint" wrote:
> I have a customer who has serveral Windows XP machines that keep dropping the
> Domain Admins group from the Local Administrators group. I have seen this in
> the past where users would remove Domain Admins but the users at this
> customer don't have the ability to do so.
>
> If we rejoin the PC's to the domain it fixes it for a while but eventually
> it drops the group again.
no doubt you already checked this, but as you haven't mentioned it:
could somebody of created a restricted groups policy
(
http://www.microsoft.com/resources/d...ictgroups.mspx) ?
strange it only appears on a few clients, but this would be possible by
filtering the GPO by computer account