Re: Remove Domain Admins ability from "Delegation Of Control"
- From: "DV" <clubv@xxxxxxxxxxx>
- Date: 21 Dec 2005 12:05:18 -0800
Hey Jorge,
The reason is purely political. We are setting up a trust between a
partner and i do not want the domain admins adding themselves to the
restricted group which in turn will be a member of a local security
group on the trusting domain. I agree, i would of thought that it
couldnt be done, as you would only place trusted parties in Domain
Admins, but quouting from microsoft:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/ctrlwiz.mspx
"This document provides three delegation examples using the Delegation
of Control wizard in the Active Directory Users and Computers Microsoft
Management Console (MMC) snap-in. They include:
Delegate complete control of an OU.
Delegate creation and deletion of users within an OU.
Delegate resetting of passwords for all users in an OU.
Prerequisites
Part 1: Installing Windows Server 2003 as a Domain Controller
Step-by-Step Guide to Managing Active Directory
Guide Requirements
To perform these procedures, you must be a member of the Domain Admins
group or the Enterprise Admins group in Active Directory, or you must
have been delegated the appropriate authority. In addition to
implementing the common infrastructure, the following steps must be
completed.
"
To me this reads as, along with Domain Admins and Enterprise Admins any
one who is delegated the appropriate permission can use the Delegation
of Control.
thanks again
.
- Follow-Ups:
- Re: Remove Domain Admins ability from "Delegation Of Control"
- From: Paul Bergson
- Re: Remove Domain Admins ability from "Delegation Of Control"
- References:
- Remove Domain Admins ability from "Delegation Of Control"
- From: DV
- Re: Remove Domain Admins ability from "Delegation Of Control"
- From: Jorge de Almeida Pinto
- Remove Domain Admins ability from "Delegation Of Control"
- Prev by Date: Re: Any "gotchas" in using "non-internet" domain name suffixes?
- Next by Date: Re: Offsite DNS question
- Previous by thread: Re: Remove Domain Admins ability from "Delegation Of Control"
- Next by thread: Re: Remove Domain Admins ability from "Delegation Of Control"
- Index(es):
Relevant Pages
|