@IRJ said in New to Windows Active Directory and Group Security Management:
Make an AD group called workstation_admins and add that group to local administrators account on each desktop. This group does not need any AD rights and nobody's account should be in there except for IT admin accounts. Even those IT admin accounts should not be used on local desktops to login on a regular basis. Only when elevation is actually needed, and even then you should use run as.
I do this - Those who need it have a workstation admin account and a local non admin normal account.