local and domain 'administrator' account

From: Peter (pmkdatabase@yahoo.ca)
Date: 01/04/03


From: Peter <pmkdatabase@yahoo.ca>
Date: Sat, 04 Jan 2003 17:04:58 +0700


The Microsoft Windows 2000 Administrator's Pocket Consultant states:

"In a Windows 2000 domain, the Administrator local user is a member of
Domain Admins (and Enterprise Admins) by default. This means that if
someone logs on to a computer as the administrator and the computer is
a member of a domain, the user will have complete access to all
resources in the domain. To prevent this, you can remove the local
Administrator account from the Domain Admins (and Enterprise Admins)
group."

This has got me a bit confused. I don't see a 'local' administrator in
these groups, only the builtin domain 'Administrator' account. Surely
that is not the same account - in my domain they have different
passwords, for starters. What am I missing?

Thanks,

Peter



Relevant Pages

  • Re: How to change domain administrator to limited/restricted user?
    ... Depending on the number of users, computers, member servers and the rest of the infrastructure, I might be tempted to start over. ... If it's "a" domain administrator, then remove the user from the ... Are the individual users direct members of the Domain Admins group or members of a group added to the Domain Admins group. ... Check a workstation or two and see if the user is a member of the local workstation administrators group. ...
    (microsoft.public.windows.server.sbs)
  • Re: ADMT v3 - cant migrate SID history
    ... use an account in the target that is a member of domain admins in the ... >> entered must have Administrator privileges on the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remove domain with no domain controller
    ... Is the account you are logging on with a member of Enterprise Admins? ... For example, even if you are an administrator in domain A, you don't have ... permission to delete a domain controller in domain B. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS Nightmare - Cant create forward zone
    ... Administrator Account (Member Off Enterprise admins and member of Domain ...
    (microsoft.public.win2000.active_directory)
  • Re: Domain Admins Security Group Message In Backup
    ... Are you logging in as *the* built-in Administrator account? ... How does your Member Of: ... > says that I do not have access and must be in the Domain Admins Security ... I am logged in as the Server Administrator and it has only just ...
    (microsoft.public.windows.server.sbs)

Loading