Re: domain local backup operators and server operators groups question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Those two groups aren't really local groups, they are built-in groups. They are special in that the SID of the groups does not have domain affinity. What I mean by that is that the SID does not have the Domain SID in the group SID. So for instance, backup ops SID on ALL Windows NT and better machines around the world is

S-1-5-32-551

Where a normal domain local group will have a SID with the domain SID in it for instance

The SID for account JOE is S-1-5-21-1862701446-4008382571-2198042679
The SID for account JOE\dlg1 is S-1-5-21-1862701446-4008382571-2198042679-21169

Without domain affinity, any object can only have relevance to security on the machines that share the same SAM. So that narrows it down to domain controllers sharing builtin groups across all DCs of a domain and non-DCs not sharing those builtin groups with ANY other machines.


So for the answers to your questions which should be obvious now

1. No Backup Ops from a domain can only work with DCs. This has been this way forever with NT and above.

2. Srv Ops only have rights on domain controllers. And again this has been the same forever with NT and above.

Your last question is answered by the above as well when you think about the scope of the SID of the groups as I described.

joe



--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



djc wrote:
1) I have always assumed that membership in the 'domain local' Backup
Operators group meant you could perform backups on any computer in the
domain. I have recently come accross information that states that members of
this group can perform backups ONLY on domain controllers. Which is correct?
And was there a change from 2k to 2k3?

2) Similarly, I have always assumed that the 'domain local' Server Operators
group had the server operator related user rights on ALL servers in the
domain and I have recently come accrose information that states that the
members of this group have these rights ONLY on domain controllers. Which is
correct? and was there a change from 2k to 2k3?

answers to 1 and 2 above would be greatly appreciated but in addition to
this the bigger question that this raises to me is this:
When speaking of 'domain local' group 'scope' for buitlin groups that exist
for 'roles' more or less (meaning they have a particular set of user rights
assigned to them to accomplish certian tasks like performing backups'), is
it true that these rights are ALWAYS only on domain controllers and not all
servers or computers in the domain? Obviously I'm trying to find a simple
rule to just remember.

any input is appreciated. Thanks.


.



Relevant Pages

  • Re: Folder/Drive Permissions
    ... If by Sid you are referring to some sort of session ID for whatever ... server administrative section, and all were (if not GUI, which I don't ... my desk with no network and no one but myself to do anything on God's ... green earth I want to it, does MS put in all this "rights" crap and not ...
    (microsoft.public.windows.vista.security)
  • Re: Folder/Drive Permissions
    ... Activate the real Administrator account and use that. ... If by Sid you are referring to some sort of session ID for whatever ... server administrative section, and all were (if not GUI, which I don't ... green earth I want to it, does MS put in all this "rights" crap and not ...
    (microsoft.public.windows.vista.security)
  • Re: Folder/Drive Permissions
    ... SID? ... Well-known security identifiers in Windows operating systems ... server administrative section, and all were (if not GUI, which I don't ... green earth I want to it, does MS put in all this "rights" crap and not ...
    (microsoft.public.windows.vista.security)
  • Re: Local Group Migration on SAN Disk
    ... same OU keeping the same server name and IP. ... move the file server to new hardware new OS Srv 2003 std (old was srv 2000 ... hundred local groups to secure the folders that we add to global groups. ... SID - would not resolve the local group name. ...
    (microsoft.public.windows.server.migration)
  • RE: local groups on member servers after admt migration
    ... SID but SIDHistory enable it to keep the old SID in its attribute. ... ADMT will replace the old sid with the new sid. ... if I have to worry about used local groups on ...
    (microsoft.public.windows.server.migration)