Re: Administer DC at remote site without domain admin rights

From: Roger Abell [MVP] (mvpNoSpam_at_asu.edu)
Date: 10/27/04


Date: Tue, 26 Oct 2004 22:37:06 -0700

Steve has provided a number of excellent ideas/pointers.
You should by all means see whether your scenario(s) can be
done through those methods.

If it is necessary that the person must be an admin for the DC
you can make them a member of the domain\Administrators
group instead of domain\Domain Admins
This will limit the person to being an admin (on every DC, not
just the one you intend) but will not confer the wider scope of
administrative access that Domain Admins carries.

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCDBA,  MCSE W2k3+W2k+Nt4
"bitwrangler" <newsgroups@hartmanhomes.com> wrote in message 
news:fqhtn0p8mh7t2gg1m78bo6rkhfcqbov3rt@4ax.com...
>I have a server at a remote site that is a domain controller (W2k3
> standard).  I would like to give a user the ability to be an admin on
> the local box without being a domain admin.  Being that there is no
> local logon now that it's a DC, I think I may be out of luck but
> wondered if anyone had a suggestion?
>
> Greg 


Relevant Pages

  • Re: Prevent Admin Logon to RWW
    ... 'Administrator' does not have RRAS rights, if I wish to VPN to a server I do ... OR since the introduction of RWW RDP Proxy I would prefer ... My preference is not to lock out the domain admins from RWW, ... you can still do remote admin work ...
    (microsoft.public.windows.server.sbs)
  • Re: List Level Security problem - Please help!
    ... If I installed and created the top level site and I'm in the Domain Admins ... I'm listed as the portal server admin. ... this setting is only supported on WSS not SPS but I have played with it ... I created a list called Security Events ...
    (microsoft.public.sharepoint.portalserver)
  • Re: smtp AD site Link versus IP AD Site Link
    ... the Enterprise admin group, i will do both, also i am testing to increase the ... bandwidth to see if this help relief the problem, could you give me an idea ... about how to test if the network connection is suitable for AD replication ... > EA only gives you so many permissions; domain admins is what gives you ...
    (microsoft.public.win2000.active_directory)
  • Re: Admin Shares
    ... computer, click Start->Run, type \\<The local computer name>\C$. ... workgroup, domain admins doesn't exist)? ... > Subject: Admin Shares ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Domain Rights
    ... Domain Admins ... Such as if you have given each user local admin rights on their ... Create a new OU for computers. ...
    (microsoft.public.windows.server.active_directory)