Re: AD administrators and domain admins groups



Domain Admins is a group with domain affinity, so that means that you can add Domain Admins to groups on machines anywhere that trusts the domain (workstations, servers, other domain's, etc). This is why you can manage workstations, etc in the domain if you have domain admins rights, the domain admin group was added the local admins groups on the machines.

Other than that, look at the ACLs on AD objects and that will tell you what an Admin can do versus a Domain Admin or even an Enterprise Admin. The permissions do vary, however, any one of those groups can easily attain the permissions of the other on a DC.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



OM wrote:
Hi,

What is the main difference, in terms of user privilege, between the administrators group and domain admins group in active directory? Accounts in either groups allow me to manage AD. It seems that only the domain admins group can administer domain workstations and servers.

Thanks

OM
.



Relevant Pages

  • Re: Rights and Permissions of Domain Admins group in AD
    ... Domain Admins does have special rights in W2K from what I remember, ... > In a native-mode Active Directory environment, ... > domain controllers and on member servers and workstations? ...
    (microsoft.public.win2000.security)
  • Re: Active directory Group Policy (Win2k)
    ... When I enforce the policy onto the computers in the new OU, ... Domain Admins so the Domain Admins cannot view ... workstations, to access Microsoft Office. ...
    (microsoft.public.security)
  • Re: Access Denied to add wkstation to a domain.
    ... You need to enter the credentials for a domain administrator such as a ... member of the domain admins group or a user that has been delegated the task ... ten workstations to the domain and after that they can not any more. ... Client User Name: Administrator ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Customize User Rights for Domain Admins Group
    ... workstation administrators members of the Domain Admins group for them to ... Add your new group and Domain Admins. ... Then link this GPO to your OU's that contain your workstations and your ...
    (microsoft.public.windows.server.active_directory)
  • Re: Rights and Permissions of Domain Admins group in AD
    ... > Domain Admins does have special rights in W2K from what I remember, ... > all workstations/servers will have domain admins in the local SAM of each ... >> rights and permissions from residing in the Administrators group on the ... >> domain controllers and on member servers and workstations? ...
    (microsoft.public.win2000.security)