Re: Domain Admin Share

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



We want to be able to connect to the admin share on any pc in the old domain.

I believe that only the NT Domain Admins have that right by default.

We can open User Manager and do some administrative stuff but it still asks
for credentials when you try to connect to an admin share.

"Paul Bergson" wrote:

I'm not sure I understand your question, but if the AD domain admins have
admin rights on the box in question they should be able to administer the
share or create/delete it.

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

"KingBuzzo" <KingBuzzo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E08E7A28-111C-4CEC-8474-F779C13FE294@xxxxxxxxxxxxxxxx
Ok, I was able to add the Domain Admins from the AD Domain to the
Administrators NT Group. Now I can administer the NT Domain but I still
have
the issue of connecting to any admin share in the old domain.

I understand that only the Domain Admins NT Group has this right.

Is there another way to do this?

"KingBuzzo" wrote:

That sounds easy enough.

However, when I go to add users to the NT Domain Admins Group, I only see
a
list of the NT Domain Users and it doesn't give me an option to select
another domain.

Do I have to add them to a local group first or use the command line?

Thanks!

"Paul Bergson" wrote:

Just add the domain admins to your NT admins group. When you go to add
members be sure to select the 2003 domain. That is all there is to it.

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no
rights.

"KingBuzzo" <KingBuzzo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F336780C-A67F-462C-9E71-4466FA7B17D3@xxxxxxxxxxxxxxxx
Hi Fellas:

I am testing the following scenario:

Domain A is W2K3 AD.

Domain B is NT4.0

I am using ADMT to migrate my users from the old domain to the new
domain
in
stages.

If I migrate my Admins from Domain B to Domain A, how can they
effectivly
manage Domain B during the staged migration. How will they be able
to use
the NT domain tools or connect to an admin share without
authenticating
everytime.

I have already set up to two way trust but I cannot grasp how to add
the
AD
Domain Admins group to the NT Domain Admins group.

Thanks!






.



Relevant Pages

  • Re: Administrators Group in Local Users and Groups
    ... Anyone who gives non-domain admins the ability to log on interactively or modify system files/services on a DC is asking to be spanked at some point in the future. ... I imagine adding themselves to the domain admins group would require a trick similar to the NT4 days where you could make cmd.exe launch as the screensaver (which runs under the local system account), then within the newly opened CMD prompt window, add your self to the local administrators group using the net user command. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remove Domain Admins
    ... >>Is there any need to leave enterprise admins with any Exchange ... remove untrusted people from your Domain Admins group instead of putting ... > I did the regedit and prevented inheritable permissions ...
    (microsoft.public.exchange.admin)
  • Re: Applying a policy to 2 machines at domain user level.
    ... Hello Tim as Jimmy says deny apply policy right for the Domain Admins Group. ... Click Properties for the particular GPO, Click Security Tab here you can ...
    (microsoft.public.win2000.group_policy)
  • Re: Security permissions bug or inheritant permissions??
    ... > What Joe has already said is that there is already granularity available, ... remove them from the domain admins group and use delegation to set ...
    (microsoft.public.win2000.active_directory)
  • Re: Prevent changes to Administrator password
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... Restricted Admins group to mitigate against what you propose Deji. ... you need to understand that permissions on the ...
    (microsoft.public.windows.server.active_directory)