Re: create support admin user

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/17/05


Date: Thu, 17 Mar 2005 13:04:03 -0600

Any user can be given the right to logon to a domain controller by
configuring the "logon locally" user right in Domain Controller Security
Policy. Then you can add the user to privileged groups shown in Active
Directory Users and Computers such as DHCP administrators and DnsAdmins. As
far as troubleshooting applications they will have limited ability without
being an administrator but you can test that out to see if it suits your
needs by using privileged groups. Server operators is another group that you
may consider that will give the user more power but the user can then create
and delete shares but will not be able to create/delete OU's or manage
administrator accounts. --- Steve

"DebraH" <DebraH@discussions.microsoft.com> wrote in message
news:E8501DBE-5CD5-4726-9FCF-A1A099473F7B@microsoft.com...
> How do I make someone an admin but take away their rights to making
> changes
> within Active Directory? I would like to give a support user the ability
> to
> logon to Domain Controllers to troubleshoot DHCP, DNS and some
> applications
> that run on the server, but I do not want them to have the ability to make
> changes to Active Directory (create or delete OUs, delete admins etc).
>
> Thanks
> dhodgkins61@comcast.net
>



Relevant Pages

  • Re: administrator unable to logon interactively
    ... Windows 2000 domain controller. ... note that the deny interactive logon permission ... so that if the Administrator is in a group like Everyone ...
    (microsoft.public.win2000.security)
  • Administrator unable to log on Interactively
    ... administrator is not able to log on interactively. ... on to the primary domain controller. ... one of the computers in the domain after I logged in as ... "Logon failure: The user has not been granted the ...
    (microsoft.public.win2000.security)
  • Re: Urgent Policy question
    ... Well the solutions I listed should work for you if you can not logon to ... >> able to logon to a domain controller locally unless you changed both ... >> and Domain Controller Security Policy. ... >> administrator or entering domain administrator credentials when you try ...
    (microsoft.public.win2000.group_policy)
  • Re: Urgent Policy question
    ... able to logon to a domain controller locally unless you changed both Domain ... share to restore default user rights for Domain Controller Security Policy. ... administrator or entering domain administrator credentials when you try to ...
    (microsoft.public.win2000.group_policy)
  • Re: Local Admin account deleted Help !
    ... Once you promote the server to a Domain Controller, the ability to ... logon to a local account is disabled. ...
    (microsoft.public.windows.server.active_directory)