Re: Grant Administrative Access to a Domain Controller
- From: "nbel007" <nbelfour@xxxxxxxxxxxxxxx>
- Date: 28 Dec 2006 06:30:16 -0800
You can even keep it simpler than that, if your domain group is nested
inside of the domain admins group, all you would have to do is is
simply deny the domain group full control at the domain root level of
active directory, since deny permissions within AD take precedence,
members of that group will have no permissions within AD, but will
still retain admin rights on the server itself, I have tested this and
found this to be the case.
MPerrault wrote:
Joe Richards [MVP] wrote:
Then you aren't dealing with very informed people. Getting into AD that
you have no rights in but you do have access to isn't all that involved.
If you already have rights it is that much easier.
--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net
---O'Reilly Active Directory Third Edition now available---
http://www.joeware.net/win/ad3e.htm
Of course you can lock yourself out of AD. I've seen it happen all the
time.
Michael P. Perrault
MCSE, CCNA, A+, MBA
Senior Systems Engineer,
ScriptLogic Corporation
Michael.Perrault@xxxxxxxxxxxxxxx
www.scriptlogic.com
http://groups-beta.google.com/group/scriptlogic-desktop-authority
If you remove domain admins group from perms in AD you remove there
Domain Admins privledges, same if you Deny them access. They can still
log onto the machine but will have no AD control.
Michael P. Perrault
MCSE, CCNA, A+, MBA
Senior Systems Engineer,
ScriptLogic Corporation
Michael.Perrault@xxxxxxxxxxxxxxx
www.scriptlogic.com
http://groups-beta.google.com/group/scriptlogic-desktop-authority
.
- Follow-Ups:
- Re: Grant Administrative Access to a Domain Controller
- From: Joe Richards [MVP]
- Re: Grant Administrative Access to a Domain Controller
- References:
- Re: Grant Administrative Access to a Domain Controller
- From: Jorge Silva
- Re: Grant Administrative Access to a Domain Controller
- From: Jorge Silva
- Re: Grant Administrative Access to a Domain Controller
- From: Jorge de Almeida Pinto [MVP - DS]
- Re: Grant Administrative Access to a Domain Controller
- From: MPerrault
- Re: Grant Administrative Access to a Domain Controller
- From: Joe Richards [MVP]
- Re: Grant Administrative Access to a Domain Controller
- From: MPerrault
- Re: Grant Administrative Access to a Domain Controller
- From: Joe Richards [MVP]
- Re: Grant Administrative Access to a Domain Controller
- From: MPerrault
- Re: Grant Administrative Access to a Domain Controller
- Prev by Date: Re: ADmodcmd & Query
- Next by Date: Re: Grant Administrative Access to a Domain Controller
- Previous by thread: Re: Grant Administrative Access to a Domain Controller
- Next by thread: Re: Grant Administrative Access to a Domain Controller
- Index(es):
Relevant Pages
|