Re: Giving admin rights to a subset of computers



Probably the best way is implement Group Policy Restricted Groups at the OU
level for the computers you want this to happen on. See the link below for
more details. I would create a global group and add it to "this group is a
member of" for administrators at the OU level. Doing it at the OU level will
prevent the users from being address to the administrators group for the
domain assuming that domain controllers are not in the scope of management
of that GPO at the OU level which they would not be if all are in the
default domain controllers container. --- Steve


http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

"Marty" <Marty@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7B660EFC-C3B8-4019-978D-447BC423C75B@xxxxxxxxxxxxxxxx
>I would like to give a certain user (or group) full administrator rights to
>a
> subset of machines in my domain, without making them members of the
> 'Domain
> Admins' or 'Administrators' group. Is this possible?


.



Relevant Pages

  • AD Problem! Please Help!
    ... getting errors in AD Users and Computers. ... Specifically when opening groups ... "A global catalog cannot be contacted to retrieve the icons for the member ... I see no errors whatsoever on my contoso.corp.com domain controllers. ...
    (microsoft.public.win2000.active_directory)
  • Re: Split AD and Server Administration
    ... If you do not need them to do all that on domain controllers then you can ... domain controllers without being in the administrators group for the domain, ... > of Windows Servers. ... > while only having the ability to add/remove computers from AD. ...
    (microsoft.public.win2000.security)
  • Re: Allowing a Domain User Admin Rights to a Couple of Domain Servers
    ... > that Domain Admins members are in the default members of each ... > machine local Administrators group on the members of the domain. ... >> If they're domain controllers, then you're pretty much out of luck. ...
    (microsoft.public.windows.server.security)
  • Re: Non domain admins installing software on domain controllers
    ... > of domain controllers and member servers distributed through out ... > object for administrators within each country and for member server we ... > domain controllers in that they cannot perform the action because they ... > install patches as and when they become available. ...
    (microsoft.public.win2000.security)
  • Non domain admins installing software on domain controllers
    ... object for administrators within each country and for member server we ... domain controllers in that they cannot perform the action because they ... the local admin group. ... install patches as and when they become available. ...
    (microsoft.public.win2000.security)