Re: How to make give cross-domain "Domain Admins" permissions



But the domain local "Administrators" group does not have some privileges
that "Domain Admins" do.

Domain Admins don't have any special permissions, the group is simply a
member of administrators on every domain member and the
builtin\administrators group of the domain. If you've added a group to the
Administrators group of the EUROPE domain it has the same level of
permissions over the DCs and AD as the EUROPE\Domain Admins group.


I don't want to have admin privileges over all member
servers/workstations,
instead I'm just trying to give a single group "EUROPE\Directory Service
Group" domain admins rights over all the domains in the forest.

Then you need to add that group into the Administrators group (of the
domain) in each domain.


These rights should allow them to modify AD Topology/replication,
view/create/modify existing GPOs, among others..

Yes, this will grant them all that.

There are security implications here. It should be noted that there should
be very few people with total control over the forest, so be very careful
with who's a member of this group. Monitor the membership and use
restricted groups to enforce the membership of this, and the administrators
groups.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net



.



Relevant Pages

  • Re: AD Design
    ... Within a new domain the domain admins can administer the complete domain, ... If you add them to the Enterprise admins, they are able to administer the complete forest. ... By default, this group is a member of the Administrators group on all domain controllers, all domain workstations, and all domain member servers at the time they are joined to the domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Opening workstation event view = Access Denied
    ... You can add domain groups (or user accounts) to local groups using Restricted Groups in a GPO. ... In a domain of any size, you might NOT want the people that administer workstations to be Domain Admins. ... You can then designate which user accounts are workstation administrators without also granting them administrative rights to the whole domain. ... being a member of the Domain Admins group does NOT necesarily mean you are an administrator on the domain member computer. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Opening workstation event view = Access Denied
    ... Domain Admins gets added to the local group called Administrators. ... being a member of the Domain Admins group does NOT necesarily mean you ... Remote Desktop Users pmd.local/Builtin ...
    (microsoft.public.windows.server.active_directory)
  • Add groups to Local Admin group
    ... I created a .bat file with the following command... ... >the local PC's Administrators group. ... >another domain group to also be a member of the ... >be a member of Domain Admins. ...
    (microsoft.public.win2000.security)
  • Re: difference in groups
    ... Administrators is a built-in group. ... group, except that local, when considered on DCs, covers all DCs. ... Domain Admins is a global group that is automatically added to the ... administrators group of every domain member. ...
    (microsoft.public.windows.server.active_directory)