Re: Domain Admin Share

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I'm not sure I understand your question, but if the AD domain admins have
admin rights on the box in question they should be able to administer the
share or create/delete it.

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

"KingBuzzo" <KingBuzzo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E08E7A28-111C-4CEC-8474-F779C13FE294@xxxxxxxxxxxxxxxx
Ok, I was able to add the Domain Admins from the AD Domain to the
Administrators NT Group. Now I can administer the NT Domain but I still
have
the issue of connecting to any admin share in the old domain.

I understand that only the Domain Admins NT Group has this right.

Is there another way to do this?

"KingBuzzo" wrote:

That sounds easy enough.

However, when I go to add users to the NT Domain Admins Group, I only see
a
list of the NT Domain Users and it doesn't give me an option to select
another domain.

Do I have to add them to a local group first or use the command line?

Thanks!

"Paul Bergson" wrote:

Just add the domain admins to your NT admins group. When you go to add
members be sure to select the 2003 domain. That is all there is to it.

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no
rights.

"KingBuzzo" <KingBuzzo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F336780C-A67F-462C-9E71-4466FA7B17D3@xxxxxxxxxxxxxxxx
Hi Fellas:

I am testing the following scenario:

Domain A is W2K3 AD.

Domain B is NT4.0

I am using ADMT to migrate my users from the old domain to the new
domain
in
stages.

If I migrate my Admins from Domain B to Domain A, how can they
effectivly
manage Domain B during the staged migration. How will they be able
to use
the NT domain tools or connect to an admin share without
authenticating
everytime.

I have already set up to two way trust but I cannot grasp how to add
the
AD
Domain Admins group to the NT Domain Admins group.

Thanks!





.



Relevant Pages

  • Re: NT4->2003 Computer Account Migration Problem
    ... win2k3 domain, domain admin is by default the computer's local admin. ... and remigrate the computers using a specific account to perform migration ... Add NT Domain Admin to Win2k3Dom Domain admins group and Win2k3Dom ...
    (microsoft.public.windows.server.migration)
  • Re: Grant Administrative Access to a Domain Controller
    ... you have no rights in but you do have access to isn't all that involved. ... Author of O'Reilly Active Directory Third Edition ... If you remove domain admins group from perms in AD you remove there ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admin Share
    ... Domain Admins have special rights to the domain by default. ... Administrators only have rights to the DC. ... I believe that only the NT Domain Admins have that right by default. ... Domain Admins group to the NT Domain Admins group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain user with local administrators right
    ... domain account to the domain admins group, this is in turn a member of the ... with this domain account (selecting the domain from the drop down box under ... If the server is a domain controller, then there is no local administrators ... group so membership of domain admins should suffice. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Verifying a user is a domain admin (with a renamed Domain Admin group)
    ... If you search for the domain admins group SID: ... A global group whose members are authorized to administer the domain. ... By default, the Domain Admins group is a member of the Administrators group on all computers that have joined a domain, including the domain controllers. ...
    (microsoft.public.windows.server.active_directory)