RE: local administrator on a domain controler...



Make the account a member of one or both of the following groups:

Account Operators (which can log on locally, Shut down the system and has
no members, and it can create and manage users and groups in the domain,
including its own membership and that of the Server Operators. This group is
a service administrator because it can modify Server Operators, which in turn
can modify domain controller settings. As a best practice, leave the
membership of this group empty and do not use it at all for any delegated
administration)

Server Operators (which can Back up files and directories, Change the system
time, Force shutdown from a remote system, Allow log on locally, Restore
files and directories, Shut down the system)

The rights associated with each group are defined in this white paper:
http://www.microsoft.com/downloads/details.aspx?familyid=631747a3-79e1-48fa-9730-dae7c0a1d6d3&displaylang=en

-Allen Firouz

"rbus" wrote:

> Hello !
>
> I need to set up an administrative account which can log on a w2k3 DC.
> This account must be able to logon, to start and stop services but not to
> administrate the full domain nor access to administrative shares on remote
> computers.
> Do you know how could I do that ?
>
> Thanks !
> Cheers
> rb
>
>
>
.



Relevant Pages

  • Re: XP Home with Two Administrators - Aggravations
    ... Check the group membership of the user and administrator to see if both users have the same group membership. ... In XP Home you need to boot into Safe Mode and logon as an administrator to examine folder NTFS permissions to see if there are any permissions that may be causing the problem. ... My understanding is that Administrators should be able to view and work with system folders, change Internet settings, etc. ... In addition, when the first administrator changes personal settings, they often propagate to the other administrator's account. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Restricted group implementation
    ... If I query WMI about local administrator member will I get the removed ... this is normal GPO behaviour. ... account has to be in an OU to which is GPO linked, ... same group membership for more than one computer. ...
    (microsoft.public.windows.group_policy)
  • Re: Restriction
    ... Only a user that is also in the local administrators group ... can manage membership in the local administrators group. ... 'change my account type' and make themselves administrator. ... My question is, as administrator, how do you change the limited account ...
    (microsoft.public.windowsxp.security_admin)
  • admin account
    ... I have been reading in this group that the "Administrator" account should be ... demoted for security reasons. ... I tried to remove its membership as a Administrator, ...
    (microsoft.public.win2000.security)
  • Re: Event 1202 Warnings after Renaming Administrator Acct on SBS2003
    ... policy to rename the account although it is not really necessary or useful. ... Did I check Group Policies for references to the Administrator ... Failed to perform redirection of folder Desktop. ...
    (microsoft.public.windows.server.general)