Re: Logon Using Terminal Services GPO



How to be administrator of the DC Server without being domain admins ?

I created a test account, only member of the builtin administrators groups.
I can create AD account, modify domain admins members & co.
That's domain admins power for me !


--
Cordialement,
Mathieu CHATEAU
http://lordoftheping.blogspot.com


"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message news:%23w5$McN4HHA.5160@xxxxxxxxxxxxxxxxxxxxxxx

"Mathieu CHATEAU" <gollum123@xxxxxxx> wrote in message news:%23RIV5W%233HHA.3600@xxxxxxxxxxxxxxxxxxxxxxx
You can create a GPO that only apply to this DC.
Use GPMC if not already.
Add a security filtering on the GPO, so it apply only to this DC.

Take care, being admin of DC means admin of the Domain. They may change your GPO to get full access anyway

Actually being in Administrators does not mean they are admin
of the domain, they need to be in Domain Admins for that.
However, it does mean they could easily elevate their account
to Domain Admins membership.

To poster:
Limiting them to RDP login on one DC, as Mathieu has indicated via
a GPO impacting only the intended DC, will not really gain you much.
Once on there they only need to open up any of a number of remote
management tools and set the focus to DC of choice.
If you do not have trust then do not extend trust.
There is no middle ground.

Roger

"Mathew V" <mvlandys@xxxxxxxxx> wrote in message news:1187247447.765096.311480@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi All,
I've searching high and low for an answer but it doesn't look like
anyone has asked this question before. The company I work for has 5
domain controllers (all in separate locations - Aus, UK, India etc).
The company's main IT Dept (who I work for) admins all these servers,
though recently we have employed some systems admin contractors to
look after the AD servers in India.

The server is in a rack with no monitor attached so the only way for
these guys to log in is via RDP/Terminal Services. I have added their
user account in "Domain Controller Security Policy" -> "User Rights
Assignment" -> "Allow log on through Terminal Services".

So now they can logon remotely and administer the server (check event
logs, create users etc). I have also given them the right to shut down
the server, as from time to time they may need to bounce the server
for hardware upgrades etc.

Though I do not want them having RDP access or shutdown other servers
within the domain. Unfortunately the GPOs that I've edited give these
users those permissions throughout all domain controllers.

Is there a way to specify which domain controllers I want these users
to be able to RDP & shutdown.





.



Relevant Pages

  • Re: Domain user with local administrators right
    ... domain account to the domain admins group, this is in turn a member of the ... with this domain account (selecting the domain from the drop down box under ... If the server is a domain controller, then there is no local administrators ... group so membership of domain admins should suffice. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ISA Server Error
    ... Since I have just been testing, I installed as one of my domain admins, ... that account is listed in the full isa rights, as well as BUILTIN/Admins, ... To be ale to syncronize the DC on the ISA server, ... My ISA_2 server is pointing to my new DC_2 server for DNS ...
    (microsoft.public.isa)
  • Re: Administrator account does not have suficent privileges to cre
    ... I am using the administrator account of the domain on the original server. ... The account is a member of the Domain Admins account. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admins Group -- Trying to trim membership
    ... very trusted and competent people being domain admins. ... a qualified regular domain user by managing AD object permissions. ... server, installing a Certificate Authority, etc. usually are not done every ... controllers are only domain controllers running DNS and not also a print, ...
    (microsoft.public.win2000.security)
  • Re: Password Problem with Server Login
    ... We periodically reboot our server and had ... login with the Administrator account like we usually do and the ... We also tried an account ... however we have other users who are members of the "Domain Admins". ...
    (microsoft.public.windows.server.active_directory)