Re: Allowing a Domain User Admin Rights to a Couple of Domain Servers

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 06/30/05


Date: Wed, 29 Jun 2005 20:58:11 -0700

This is exactly what the machine local Administrators group on
the members is used for. Provide the individual with an account
that is just a low priv domain user account, and then add this
account into the Administrators group on those two machines.
I would recommend that you do not do this with that person's
normal day-to-day usage domain account, but define one just
for the purpose so that those two machines are not placed into
jeopardy by the person's day-to-day activities. The special
account could for example be restrict for local log use to only
those two machines.

-- 
Roger Abell
Microsoft MVP (Windows  Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
<inteltech@gmail.com> wrote in message
news:1120101232.707852.206150@g47g2000cwa.googlegroups.com...
> Hello All
>
> I am looking for a little assistance...
>
> Within our company we have two servers that have a different
> administrator to the rest of the network.
>
> Currently the administrator of these servers uses the domain
> administrator username/password to perform his admin tasks on the
> server, but has also been know to use this account for other purposes.
>
> So what I would like to do, is provide him with an account that ONLY
> has administrator rights on this two machines that he requires
> administrator access too.
>
> Something like user account within Windows XP on the domain server
> would do the trick...  but no!
>
> Does anyone have any ideas/advise for this?
>
> Thanks in advance
>
> David
>


Relevant Pages

  • Re: Local Admin
    ... What it sounds like you are trying to determine is whether or not the administrator account has been changed while the OS is offline. ... If you cron'd up something that ran with system permissions you could dump this key from each of the machines every day and do a compare. ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • Re: Access and roles in DCOM technology
    ... account should definitely not be. ... The 4 servers interact via DCOM technology. ... If this user is local administrator on 4 servers everything works ... > user so the DCOM technology will work between the servers? ...
    (microsoft.public.security)
  • Re: seeing another computer on a LAN
    ... So, while I was waiting for your response, I tried creating an act on ... 2nd account, Administrator is not displayed on the logon screen, so HELP! ... Both machines are XP Pro ...
    (microsoft.public.windowsxp.network_web)
  • Re: Event 1202 Warnings after Renaming Administrator Acct on SBS2003
    ... policy to rename the account although it is not really necessary or useful. ... Did I check Group Policies for references to the Administrator ... Failed to perform redirection of folder Desktop. ...
    (microsoft.public.windows.server.general)
  • Re: MS Exchange Relay Authentication
    ... I've seen this on a few servers in various environments. ... The account was still named Administrator ... It seems that account passwords are being cracked. ...
    (NT-Bugtraq)