Re: Domain Admin Permissions

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello,

You should never change the Default Policy. You should create a separate one. Moreover, that will make them local admin of servers, which is bad.
Create a new GPO and link it to your workstation OU (if all Workstation are in the Computers container, create a new OU)

Did you read the link i provided ? You will use the "member of" part.
Right click "restricted groups", choose add
type the dev group : Mydomain\dev_admins (or use the browse to get it)
Click the Add button (the down one!)
Type directly: Administrators
check gpo is replicated between dc and applied to pc


--
Cordialement,
Mathieu CHATEAU
English blog: http://lordoftheping.blogspot.com
French blog: http://www.lotp.fr


"David P." <DavidP@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:02C74DE9-EBAB-4ECD-B733-3C81639B38B7@xxxxxxxxxxxxxxxx
Thanks for the reply.
So, I created a developers admin group and then went into edit our default
domain policy. I added the Developers admin group, but do not get how to
make that group a member of the local admins group. Where does that local
admin group exist? I know there is an administrators group on each local
machine, but how to I get to it. Will that restrict the domain admins?
Thanks!


"Mathieu CHATEAU" wrote:

Hello,

Create a group for that "developpers admins"
use GPO restricted group to make that member of local admin groups.

http://technet2.microsoft.com/windowsserver/en/library/2715d832-fe71-47f7-86fd-412f013a40cd1033.mspx




.



Relevant Pages

  • Re: Securing Enterprise Policy from local admins
    ... Admin is admin. ... but it is just the fact that a local admin on the box ... >>Enterprise Policy Administration ...
    (microsoft.public.dotnet.security)
  • Re: Software Audit & Enforcement - Required?
    ... The local admin account on each laptop is disabled by default, ... get local admin access to their machine. ... well as the less likely privilege escalation bug installing software. ... unlicensed/against company policy installed. ...
    (microsoft.public.security)
  • Re: local admin account password
    ... What I think would be a better scheme is to set a very complex* random ... This eliminates the vulnerability created by weak admin passwords ... Do you think if someone wanted to break the local admin account they ...
    (Focus-Microsoft)
  • Re: Opinions needed on Windows Administrative Rights
    ... >> CAN'T GIVE USERS ANY RIGHTS! ... Issuing local admin privs is dangerous because: ... A lot of new viruses first go after anti-viruses by stopping the process ...
    (comp.security.misc)
  • Re: How can I change the admin password of all our XP PCs on the doma
    ... You don't go to each workstation and check if that user changed the local admin password. ... If the box has a problem that means you can't use a domain admin account to logon, it is usually quicker to rebuild than troubleshoot. ... If you want to control the Local Administrators on the workstations, just disable the Local Administrator, and then use another GPO or Script that adds a existing security group in your AD as member of the local Administrators on the workstations. ...
    (microsoft.public.windows.server.active_directory)