Re: Domain User -> Configure as Local Administrator



Yes, unless the particular servers are DCs themselves. You can't effectively give admins admin rights only on one or two DCs, DCs share a security database.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


WhoC@nItbN0W wrote:
Hi:

1. I need to perform separation of duties between administrators so that each has access to some particular server as an administrator and as a user on the others. (2K3 DC; mix of 2k3 and 2k servers)


2. I am planning to go about doing this by performing the following
a. Change domain administrators to domain users on the DC( except enterprise admin)
b. On a particular servers' 'local user and accts'; I add the domain user as an administrator.


3. Is this a feasible alternative? Any issues seen here by anyone before I go about implementing this? What about SMS, Updates, others?

TIA
.



Relevant Pages

  • Re: Help with setting up Sites.
    ... Site A - respresenting physical site B ... servers is increasing by the day. ... Do you have any DCs at SiteB? ... clients servers in the relevant sites to authenticate against them. ...
    (microsoft.public.windows.server.active_directory)
  • Re: adding machine to domain with NATed IPs
    ... sounds that the DCs are not reaching the>> clients ... can the servers pint the clients by IP and Name? ... we specified these IPs as DNS server within ...
    (microsoft.public.windows.server.active_directory)
  • RE: Need Advice (Repost)
    ... configuration there is no preference to the prod DCs over the DR DCs" Is ... if the DR servers are in a different AD site the users will be able to ... Active Directory Sites should be configured in this scenario. ... I've built two Active Directory Domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: build now, join later
    ... admin rights in a child domain. ... instance configure DNS for failover, ... requires more than two dozen servers, ... them to create the child domain and their DCs with it, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Renaming Admin ID - Making Sys Admins Accountable
    ... If they are 2003 member servers then you have remote access via the /console ... I think their point was that these apps dont necessarily need ... > that power user to do admin tasks because the apps have to always be ... >> /console and remotely run the console and still keep your two sessions up ...
    (microsoft.public.win2000.active_directory)