Re: Admin with no Rights to Active Directory

From: DebraH (DebraH_at_discussions.microsoft.com)
Date: 03/21/05


Date: Sun, 20 Mar 2005 18:27:03 -0800

For a help desk user, should I give them Server Operator rights? I need the
user to be able to start and shutdown server and run some services. I also
need them to manage DHCP.

"Joe Richards [MVP]" wrote:

> You can't, anyone who can make changes to services, files, etc on a DC can seize
> domain admin access rights and even Enterprise Admin rights. Do not let anyone
> but domain admins log into DCs.
>
> joe
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
> DebraH wrote:
> > How do I make someone an admin but take away their rights to making changes
> > within Active Directory? I would like to give a support user the ability to
> > logon to Domain Controllers to troubleshoot DHCP, DNS and some applications
> > that run on the server, but I do not want them to have the ability to make
> > changes to Active Directory (create or delete OUs, delete admins etc).
> >
> > Thanks
> > dhodgkins61@comcast.net
>



Relevant Pages

  • Re: SCW question.
    ... Created a new Server and installed IIS. ... and saw that the default rights for IUSR and IWAM users are there. ... Server to the domain without and GPO's applied...Local Security policy ... rights (which coincides with my Member server GPO settings). ...
    (microsoft.public.windows.server.security)
  • Re: SBS 2003 folder redirection, offline files, ..and more
    ... you log into a shared PC with admin rights and go to Windows Explorer Folder ... documents are redirected to the server. ... without redirection, they wouldn't have been. ...
    (microsoft.public.windows.server.sbs)
  • Re: file rights issue...
    ... Domain Admin has rights to everything so not being able to access the ... The Terminal Server is an entirely different ... of BV we are running uses an SQL DB engine called Pervasive SQL to ... the accounting data on the Windows 2000 server through the pervasive ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Error
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... the network or Internet, and then try again. ... You are trying to use a file that is stored on a server, ... protocols in the Player are not enabled. ...
    (microsoft.public.windowsmedia.player)
  • Re: sbs2003 to (new)server2003 user issue
    ... Meinolf Weber ... This posting is provided "AS IS" with no warranties, and confers no rights. ... sbs server dead sunday night. ... Even if the account in the domain and the local account on the ...
    (microsoft.public.windows.server.active_directory)

Quantcast