Remove Domain Admins ability from "Delegation Of Control"



Hi,

I was just wondering whether it is possible to remove the Domain Admins
group the ability to Delegate Control in active directory and allow
only a specific security group this permisson. IE Create a security
group called Delegation Admins and only allow this group the ability to
delegate control.

The scenario is as follows. I need to create a bunch of restricted
security groups and i plan on placing these under a Restricted Security
Group OU. Then i plan on removing the the Read Members, Write Members
permission from domain admins so they cannot add or remove members
within the restricted groups. Then i would create a group called
"Restricted Group Admins" or similar and give it permission to
Read/Write members and then add the Admins that do have permission to
modify the restricted group membership to this "restricted group
admins" group. Thats all fine.

What i would like is the ability to prevent Domain Admins from Re
Delegate Control of these particular attributes to themselves again..

Hope that makes sense.

Thanks for your help in advance.

Dominic

.



Relevant Pages

  • Re: Delegating control to sites
    ... If you don't already have them, create OU's for each administrative unit ... can they administer DHCP on their site? ... Work out who the backup domain admins are when you are away ... I want to remove them from Domain Admins and delegate control over ...
    (microsoft.public.windows.server.active_directory)
  • Re: Administrator levels
    ... all the techs are set up as domain ... admins, based on their job function, and I am looking for some guidance. ... like an OU to delegate control to say "DeptAdmins".) ... There are also some delegation of SERVICE stuff in a GPO under ...
    (microsoft.public.windows.server.active_directory)
  • Changing domain admins delegate control
    ... I'm running Exchange 2003 Enterprise. ... I and few admins have Full ... name, delegate control, there are ... Is it ok to change the domain admins to view admin only? ...
    (microsoft.public.exchange.admin)
  • Re: Rid AD of Circular Group Membership
    ... and have use on members if it is used there. ... Administrators group is still intact), nor do they have empowerments over ... Admins is being used for by the 30+ can be delegated I(ex. ... The quess is each has an account and uses it, ...
    (microsoft.public.windows.group_policy)
  • Re: Add another domain user group to local administrators of all computers in an OU with removing ot
    ... flexibility to add other local admin users to specific computers as ... members defined in the gpo. ... domains group policy the possibility exists it is applied to machines ... domain admins group. ...
    (microsoft.public.windows.server.active_directory)