Active Directory Admin Model

From: Neil Llewellyn (anonymous_at_discussions.microsoft.com)
Date: 05/04/04


Date: Tue, 4 May 2004 04:21:02 -0700

Hello,

Can anyone help me with the last piece of my puzzle?

The company I work for wants a distributed Administration model. There are around 22 sites in the USA and 9 sites around Europe. No one except for the Enterprise admin team is to have the domain admin passwords.

* We have a single forest and a tree made up of a root domain and two child domains... EU and NA.

* The Current NT4 domains have been collapsed into Regional OUs and authority delegated at this level to a security group (that represents their boundary of authority)above the delegation point.

* The domain Controller (DC) policies have been changed to allow these security Group members to logon locally.

* The Terminal server configuration has been altered to allow them to login to the DC's in admin mode

* They are members of server operator, DHCP ADMIN and DNS ADMIN built in groups

The problem is that at some sites the server structure has been consolidated and they need to be able to Install and manage the server as if they were logged in as local Administrator account. As you know this account doesn't exist on a DC.

Is there anything that can be configured to allow me to get the desired result?

Thanks in advance

Neil



Relevant Pages

  • Re: Secure host newbie - fun - humm
    ... decision, as the admin, whether or not to take down the server. ... Listen, as a security specialist, I *know* that every single box that I, ... some level of risk and that there is no "100% I'm secure" level. ...
    (Security-Basics)
  • Re: Server Operator Role
    ... domain admin and then keep in mind that a domain admin can get Enterprise Admin ... Joe Richards Microsoft MVP Windows Server Directory Services ... The server operator role allows ... the group cannot run the TS Policy. ...
    (microsoft.public.win2000.active_directory)
  • Re: Two Server Setup Question.
    ... That external trust factor thing ... get your admin domain up first. ... Microsoft Certified Trainer, Microsoft MVP - Windows ... Microsoft Windows & SQL Server Advisory Panel Member ...
    (microsoft.public.windows.server.setup)
  • Re: Two Server Setup Question.
    ... That external trust factor ... get your admin domain up first. ... Microsoft Certified Trainer, Microsoft MVP - Windows ... Microsoft Windows & SQL Server Advisory Panel Member ...
    (microsoft.public.windows.server.setup)
  • Re: Two Server Setup Question.
    ... a student accessed lab and the school admin machines. ... separate routers and lan wiring so that the lab could be completely isolated ... not only from the admin lan but from the outside world. ... your old server be lab.school.org. ...
    (microsoft.public.windows.server.setup)