Re: Domain Rights



No that is not possible and can not be delegated using AD permissions. By
their nature domain controllers contain very sensitive information including
a writeable copy of Active directory and need to be managed by a trusted
domain level administrator. It is possible to dcpromo a domain controller
remotely if need be or manage it via Terminal Services remote
administration.

Steve


<chip33az@xxxxxxxxxxxx> wrote in message
news:1157580298.551149.166730@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

I work for a large company with several remote administrators. These
administrators need to be able to add/modify/delete accounts and
computers. They are not allowed to be Domain Administrators.

We did that through permissions on OUs and granting them rights to
local computer systems.

Is it possible to grant them rights to work on domain controllers
(install patches) without making them domain admins?

Thanks.



.



Relevant Pages

  • Re: Split AD and Server Administration
    ... If you do not need them to do all that on domain controllers then you can ... domain controllers without being in the administrators group for the domain, ... > of Windows Servers. ... > while only having the ability to add/remove computers from AD. ...
    (microsoft.public.win2000.security)
  • Re: Allowing a Domain User Admin Rights to a Couple of Domain Servers
    ... > that Domain Admins members are in the default members of each ... > machine local Administrators group on the members of the domain. ... >> If they're domain controllers, then you're pretty much out of luck. ...
    (microsoft.public.windows.server.security)
  • Re: Non domain admins installing software on domain controllers
    ... > of domain controllers and member servers distributed through out ... > object for administrators within each country and for member server we ... > domain controllers in that they cannot perform the action because they ... > install patches as and when they become available. ...
    (microsoft.public.win2000.security)
  • Re: Giving admin rights to a subset of computers
    ... level for the computers you want this to happen on. ... member of" for administrators at the OU level. ... domain assuming that domain controllers are not in the scope of management ...
    (microsoft.public.win2000.security)
  • Non domain admins installing software on domain controllers
    ... object for administrators within each country and for member server we ... domain controllers in that they cannot perform the action because they ... the local admin group. ... install patches as and when they become available. ...
    (microsoft.public.win2000.security)