Re: User access between different forests.
Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance
Yeah, this isn't as easy as you'd hope. You can't add yourself into domain
admins as its a global group. Therefore you need to create your own group
that has the same permissions and rights. Basically, there is nothing
special about domain admins. It's just a global group that is automatically
added to the administrators group on all domain members. Therefore, to
achieve the same thing with non-local members, you must create a universal
group in this domain and add yourself to this group. Then you add this
group to the builtin\administrators group on a DC and all members.
If you want to do this for non-DCs, have a look at this:
--
http://www.msresource.net/content/view/45/47/
--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net |
http://forums.msresource.net
.
Relevant Pages
- Re: Remote Desktop Sub Domain Member Servers
... Domain Admins is a global group. ... Only domain local and universal groups can contain members ... Admins to the Administrators accounts of all members of SUB. ... (microsoft.public.windows.server.active_directory) - Re: Domain and OU Permissions
... Only members of local administrators group can add other members to local ... At the moment only the domain administrator can do it. ... place the ou admins in that group and place global group in the ... >> local admins group. ... (microsoft.public.windows.server.active_directory) - Re: Rid AD of Circular Group Membership
... and have use on members if it is used there. ... Administrators group is still intact), nor do they have empowerments over ... Admins is being used for by the 30+ can be delegated I(ex. ... The quess is each has an account and uses it, ... (microsoft.public.windows.group_policy) - Re: Add another domain user group to local administrators of all computers in an OU with removing ot
... flexibility to add other local admin users to specific computers as ... members defined in the gpo. ... domains group policy the possibility exists it is applied to machines ... domain admins group. ... (microsoft.public.windows.server.active_directory) - Re: Add another domain user group to local administrators of all computers in an OU with removing ot
... If you have a group "mylocaladmins", which is added to restricted groups, ... if you have a lot of local admins you can have a lot of more problems. ... Select add on the Members of this group and then add the members ... machines you may not want it applied to. ... (microsoft.public.windows.server.active_directory) |
|