Help Fix - Account Operator can access domain admin groups/users

From: Staraider (staraider@mydomain.com)
Date: 10/10/02


From: "Staraider" <staraider@mydomain.com>
Date: Thu, 10 Oct 2002 07:47:41 -0400

I have discovered that the Account operator rights ...for some
reason...allows access to add/remove users to the domain admin group and
modify the domain admin users.
Because of this, I can not delegate account op rights to some of my sites.

This only happens in one of my 2 NT4 domains.

I closely examined all the SIDS for the groups and they are the
correct.defaults.

Something at a deep level has been corrupted, over the years, to allow
this.

I plan to migrate to W2K....but I do not want to inherit this problem, I
would like to fix this opposed to build a complete new domain and recreate
all the groups.

1 any help to fix the NT4 problem appeaciated
2 Any suggestion on if this problem would migrate with W2K domain upgrade



Relevant Pages

  • Re: Reg .software installation previllages
    ... As a rule I highly disagree with restricting what Domain Admin users ... by GPO or any means. ...
    (microsoft.public.win2000.active_directory)
  • Domain users without access to certain folders
    ... We are setting up a couple of Domain Admin users. ... of the users to have all the permission, except for 2 folders. ...
    (microsoft.public.windows.server.active_directory)
  • Re: RWW authentication
    ... I only receive this pop up authentication for non domain admin users ... window that only domain admins are able to log into. ... messing with settings trying to get companyweb to work with the RWW. ...
    (microsoft.public.windows.server.sbs)
  • Re: Reg .software installation previllages
    ... I am running the VSS 6.0 in that server. ... out of domain admin group then VSS is not working fro the clinets. ... > As a rule I highly disagree with restricting what Domain Admin users ...
    (microsoft.public.win2000.active_directory)

Loading