Re: Administrators Group in Local Users and Groups
- From: "Spin" <Spin@xxxxxxxx>
- Date: Mon, 2 Jan 2006 12:38:52 -0500
Hi Joe,
I do not see a problem with adding junior admins to the Account Operators
group. That gives them good privileges to the domain without giving them
domain admin rights. I feel safe doing this. Why do you feel it is not
safe?
--
Spin
"Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx> wrote in message
news:uO5Ox5LDGHA.2988@xxxxxxxxxxxxxxxxxxxxxxx
> 1. You can't have a group automatically added upon join. You can get them
> added via a group policy though, look at restricted groups.
>
> 2. You can't add builtin groups from the domain to domain member's builtin
> groups. Builtin groups have a well known sid, in the case of acc ops it is
> S-1-5-32-548. That group will not work outside of domain controllers. If
> you applied it to an admin group, it would give a resolution error.
> However think of if it did work, that SID has no domain affinity (i.e. no
> domain component of the SID) so ANY account operator of ANY domain would
> then have admin rights to your workstations. That is why it doesn't work
> at all.
>
> Finally, don't use account ops. It is a bad group to use for a multitude
> of reasons. Consider it useful only during migration from NT4. Once you
> have all 2K or better DCs, stop using it.
>
> joe
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
> Mark Morrell wrote:
>> Hi!
>> I am trying to find out how to add in the domain group Account Operators
>> to
>> each workstations administrator group (without going to each computer).
>>
>> Domain Admins is added into each computer when it joins the domain.
>> I want Account Operators to do the same.
>>
>> Running Server 2000 and 2003 native
>> With Workstations 2000 and XP
>> All updates as of yesterday.
>>
>> Thanks
>> Mark
>>
.
- Follow-Ups:
- Re: Administrators Group in Local Users and Groups
- From: Jorge de Almeida Pinto
- Re: Administrators Group in Local Users and Groups
- Prev by Date: Re: monitor login
- Next by Date: Re: Created users can't immediately login
- Previous by thread: Re: monitor login
- Next by thread: Re: Administrators Group in Local Users and Groups
- Index(es):
Relevant Pages
|