Re: delegate admin rights to an user in an OU



No and you don't want them administrating the DC. If they have that level of rights they can actually take away YOUR rights. It is a few relatively simple steps to escalate from local rights to Enterprise Admin level.

In general you also don't want to use DCs for file and print, lots of nice security holes available there.

The only things in your list I would delegate would be the user stuff and the computer stuff.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Tomppa wrote:
Is it possible to give an user in a branch office so much rights with delegate control and group policies, so he could administrate their DC without help from the domainadmin?

the local admin should be able to:
- install programs that need local admin rights
- take backup
- share files
- create and share printers
- add computers to domain
- create users, reset password for other users in his OU

Is this possible with a reasonable amount of work?

Tomppa


.



Relevant Pages

  • delegate admin rights to an OU
    ... so he could administrate their DC ... without help from the domainadmin? ... install programs that need local admin rights ...
    (microsoft.public.windows.group_policy)
  • delegate admin rights to an user in an OU
    ... so he could administrate their DC ... without help from the domainadmin? ... install programs that need local admin rights ...
    (microsoft.public.windows.server.active_directory)
  • Re: Automatically making AD users local administrators on computers in SBS 2003
    ... best" when assigning user rights. ... provide the client this account and password. ... can use this special local administrator account. ... > This will automatically give each user that logs in local Admin rights. ...
    (microsoft.public.windows.server.sbs)
  • Re: Removing Local Admin Rights...
    ... > None of our users have admin rights. ... Some software will run only under local admin user accounts. ... > Ethical Hacking at the InfoSec Institute. ... > pen testing experience in our state of the art hacking lab. ...
    (Security-Basics)
  • RE: Correct setup of XP-Pro computer on Win2K Domain
    ... Setting up a local account on the xp machine does not result in local admin ... rights for that user, you need to put them in the local admin group. ... > inconsistent problems with security when I setup a new XP-Pro workstation. ...
    (microsoft.public.windowsxp.setup_deployment)

Loading