Re: Remove domain admins from local admins group on specific serve
- From: "Danny Sanders" <Danny.Sanders@xxxxxxxxxxxxxxxxx>
- Date: Fri, 21 Oct 2005 11:27:37 -0600
Are we talking about DCs or member servers?
DDS
"RA" <RA@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:495A6C78-0658-433F-A331-E130902A4FD9@xxxxxxxxxxxxxxxx
> Thanks for your reply, Here is the scenario,
>
> I have delegated full control of an OU under the main domain to a group.
> This group has full control over all servers in that OU only but are not
> domain admins. This group is also part of the local admins group on all
> the
> servers within that OU only. If one of these users removed the domain
> admins
> group from the local administrators group on one of these servers, will a
> domain admin still be able to logon to these servers? Also if they can I
> assume they will be able to add themselves back into the local admins
> group
> on the said servers as well.
>
> Thanks
>
>
> "Danny Sanders" wrote:
>
>> Actually you don't restrict the domain admin you restrict who you add to
>> the
>> group.
>>
>> One of the main criteria for being a domain admin is trust. If you can't
>> trust them they don't need to be a domain admin.
>>
>> If you could remove them, they as domain admins can undo what ever you
>> can
>> do as a domain admin.
>>
>>
>> hth
>> DDS W 2k MVP MCSE
>>
>> "RA" <RA@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
>> news:6F24C573-528B-4C55-BA04-68763B0A7788@xxxxxxxxxxxxxxxx
>> > Hi
>> >
>> > I have a few servers in an OU in which I want to assign full control
>> > only
>> > to
>> > a specific group other than domain admins. If I remove the domain
>> > admins
>> > group from the local admins group on these servers :
>> >
>> > 1. will that prevent all domain admins from logging on to these
>> > machines.
>> >
>> > 2. can they (the domain admins) then seize control of these servers and
>> > add
>> > themselves back into the local admins groups (on these machines).
>> >
>> > Thanks.
>> >
>>
>>
>>
.
- Prev by Date: Time Zone Settings at Boot Up
- Next by Date: Re: Remove domain admins from local admins group on specific serve
- Previous by thread: Time Zone Settings at Boot Up
- Next by thread: Re: Remove domain admins from local admins group on specific serve
- Index(es):
Relevant Pages
|