We currently have a policy setup on workstations which makes domain users
part of the local administrators group.

The issue is that 70% of the machines have ZCM installed and 30% do not,
and are not up to spec.

We want to be able to remove the domain users group from the workstation
local administrators group and drop the local user and authenticated users
to 'local user' status. We could do this through the AD GPO but then half
the legacy programs on the 30% would stop working because they need modify
rights to Windows.

Is there any way to do this through polices in ZCM?

Thansk for you thoughts.