RE: How to prevent some specific Domain Admin Accounts from creating U



I've done this before. (or something similar to this.)

If the groups only needs to administer the DCs, they don't need to be in the
domain admins group. They only need to be in the Built-in Administrators
group.

The process to do this is slightly different between a 2000 forest and a
2003 forest.

Create 2 groups. (i.e.- DCAdmins and DenyAD. This are mode up groups.
call them whatever you want.)

Nest the DCadmins in the Administrator group (this gets your account the
ability to administer the DC.) Next, add the DCadmins group in the DenyAD
group.

The next piece is tricky since it requires denies. I have to find my old
doc on how it was done. BUT IT IS NOT a blanket deny over the DOmainNC,
configuration, and Schema. the account that is logging into the DC needs to
be able to read a n attriute so that it knows it is allow to login to the
machine (this is for 2003 forests.)
.



Relevant Pages

  • Re: Should be a simple task
    ... the domain admins group... ... users in the child domain. ... > I want to manage the student's accounts in the parent domain but NOT have ... > which they will administer: 2 students per domain: one DC and one MS. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admin Share
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... Now I can administer the NT Domain but I still ... I understand that only the Domain Admins NT Group has this right. ... Domain Admins group to the NT Domain Admins group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Should be a simple task
    ... Has Domain Admins changed? ... > users in the child domain. ... >> I want to manage the student's accounts in the parent domain but NOT ... >> them administer the parent. ...
    (microsoft.public.windows.server.active_directory)
  • Re: New AD and DNS environments
    ... > Much, much easier to administer. ... > recommends as flat a forest as possible, and as few domains as possible. ... > You _don't_ need multiple domains for delegation of administration, ... > You _do_ need separate domains if you require separate password policies, ...
    (microsoft.public.windows.server.active_directory)
  • Re: New AD and DNS environments
    ... Much, much easier to administer. ... recommends as flat a forest as possible, and as few domains as possible. ... You _don't_ need multiple domains for delegation of administration, ... You _do_ need separate domains if you require separate password policies, ...
    (microsoft.public.windows.server.active_directory)

Loading