Re: Active Directory User Groups

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/13/05


Date: Wed, 13 Jul 2005 11:48:40 -0500

In Active Directory Users and Computers examine the membership of these
groups - administrators, domain admins, and enterprise admins. Remove
users/groups that should not be members including the Faculty Group. You can
also use Group Policy Restricted Groups to enforce and maintain membership
of domain and local groups on domain computers. --- Steve

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/gp/611.asp
  --- Restricted Groups.

"mwcanton" <mwcanton@discussions.microsoft.com> wrote in message
news:EB77AA02-77A7-4A5B-835F-9B9C7CCFDD58@microsoft.com...
> We have a Faculy Group that contains all our teacher user accounts. It was
> brought to my attension that they all have Domain Admin rights. Is there a
> tool that I can use to strip that entire group of Domain Admin rights.
> Windows Server 2003.
> Thanks



Relevant Pages

  • Re: Error using LDAP query
    ... > I have currently wrote a logon script for my domain user accounts. ... > basically query's AD for group membership and then maps drives ... > Dim oADSysinfo ... > everyone cannot be a domain admin. ...
    (microsoft.public.windows.server.scripting)
  • How to validate "Domain Admin" user?
    ... membership in "Domain Admin" group. ... member server as "LocalSystem". ... Environment is Windows 2000 AD domian. ... a non-english env or if "Domain Admin" group was renamed ...
    (microsoft.public.platformsdk.security)
  • Re: Deny administrator local login
    ... but who would be able to effect that membership in the first place? ... > domain admin accounts on workstations. ...
    (microsoft.public.windows.server.setup)
  • Re: Secure an Administative Group
    ... add/remove users to the local Administrators group. ... have "Domain Admin" privileges admin privileges on the local machines. ... Allow joining of computers to domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: I need Ideas on securing a remote Win2k machine
    ... > * You can set security filtering on a group policy object. ... > * You can set a policy to run an application at logon (your kiosk app, ... Create a new Organizational Unit for the kiosk computers and move ... suggests that I need to get the domain admin to do a lot of this. ...
    (microsoft.public.win2000.security)