Re: Administrator Accounts

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/11/05


Date: Mon, 11 Jul 2005 11:25:34 -0500

You need to be more specific in what you need the users to do with AD for
the 2 users. Full access may not be possible without making the users domain
administrators. Otherwise you can use delegation and/or privileged group
membership to accomplish much of what you want. For instance users of
backup operators group for the domain in Active Directory Users and
Computers can backup and restore domain controllers. There are also separate
user rights for backup and restore in Domain Controller Security Policy.
The backup/restore could also be granted for all domain computers if that is
your goal.

Members of account operators in ADUC can create user accounts and groups for
the domain or you can delegate authority to create users/computer accounts
and reset passwords for all but privileged group members. In other words a
user delegated that power could never reset a domain administrators
password. When you delegate for the domain/OU you can use standard or create
special permissions. The links below may help as examples of delegation
which is done via modifying AD object permissions with or without the wizard
which you can access by right clicking the domain or OU container and select
delegate control. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;221577
http://support.microsoft.com/default.aspx?scid=kb;en-us;315676
http://www.microsoft.com/windows2000/techinfo/reskit/deploymentscenarios/scenarios/ou_delegate_admin_authority_secgroups.asphttp://www.microsoft.com/windows2000/techinfo/reskit/deploymentscenarios/scenarios/ou_delegate_admin_authority_secgroups.asp

"Erl" <Erl@discussions.microsoft.com> wrote in message
news:565E43D2-67DB-4221-8559-A3B1ED9496D1@microsoft.com...
> OK, I've looked around a quite a bit and haven't found any solid answers
> for
> setting up security on administrator level accounts.
>
> Here is the scenario...
>
> We have 5 people who need to do different tasks on our Windows 2000 Domain
>
> All 5 need to be able to add accounts, reset passwords, join machines to
> domain.
> 3 need access to backups
> 2 need access to Exchange and AD - basically full access.
>
> We would also like to audit these accounts so we can see who did what and
> when.
>
> These accounts will be used for admin type things only, all users have
> their
> normal accounts for daily activities.
>
> Can someone offer some suggestions or point me to a good resource?
>
> Thanks,
> Erl
>



Relevant Pages

  • Re: Active Directory Value Proposition
    ... > backup purposes - which leads to centralized backups (including open file ... > 1) Central administration of accounts, permissions, and policy. ... > What are the risks? ... >> Would you recommend using Active Directory in a small-business setting? ...
    (microsoft.public.win2000.active_directory)
  • Re: Account Operators accessing other account operators
    ... Once you are done with that you should move to fully delegated accounts where the exact permissions needed are delegated. ... group and delegate the correct permissions on an OU that applies to the correct objects in that OU. ... the Microsoft Windows domain controller that has the primary domain controller emulator operations master role verifies the ACLs on members of these administrative groups and compares them to the ACL on the AdminSDHolder object. ...
    (microsoft.public.windows.server.active_directory)
  • Re: MS - Archive and recovery of emails
    ... asked to backup current emails so users can clean out their ... accounts of older emails. ... Have you checked the users' profiles for pictures and MP3s, ... and that any .jpg and .mp3 files kept in their normal ...
    (microsoft.public.windows.server.sbs)
  • Re: Permissions to join machine to domain
    ... I'm looking for just a list of ACL/ACE permissions to allow only joining to ... I want to delegate the following control to a group. ... Locked User Accounts: ... 294777 - How to Delegate Group Policy Control to users in Trusted Domain: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Exchange Server/Outlook 2003
    ... Assuming you just created new accounts and did not attempt to restore the ... If you restored Exchange, you probably have to run mailbox cleanup to attach ... What's the RAID and backup situation? ... > server a month later. ...
    (microsoft.public.windows.server.sbs)