Secure Domain Contollers at Branch Offices



We need to reduce the number of users in the Domain Admins group. We are
running Windows 2003 and are not looking to move to the next release for a
while. We have multi-function domain controllers at a number of branch
offices. Administrators have been placed in the Domain Admins group to
administer these servers.

How can we remove admins from the Domain Admins group but still allow them
to perform daily operations tasks on these servers (restart services, setup
printers, logon locally, manage file security... etc). Has anyone come up
with a good security model for this without compromising security too much.

Thanks

.



Relevant Pages

  • Restrict Desktop Administrators Issue
    ... I run a small Win2k native mode network with 28 servers, ... Since these guys are Domain Admins my policy restriction ... them out of the Domain Admins group or something else? ... My desktop guys need to be administrators on all the ...
    (microsoft.public.win2000.active_directory)
  • Restrict Desktop Administrators Issue
    ... I run a small Win2k native mode network with 28 servers, ... Since these guys are Domain Admins my policy restriction ... them out of the Domain Admins group or something else? ... My desktop guys need to be administrators on all the ...
    (microsoft.public.win2000.group_policy)
  • Restrict Desktop Administrators Issue
    ... I run a small Win2k native mode network with 28 servers, ... Since these guys are Domain Admins my policy restriction ... them out of the Domain Admins group or something else? ... My desktop guys need to be administrators on all the ...
    (microsoft.public.win2000.security)
  • Re: Secure Domain Contollers at Branch Offices
    ... Administrators have been placed in the Domain Admins group to ... administer these servers. ... How can we remove admins from the Domain Admins group but still allow them ... with a good security model for this without compromising security too much. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Restrict Desktop Administrators Issue
    ... Use the Restricted Groups section of Group Policy to add Desktop Support ... to the local Administrators group on the individual workstations. ... > admins are members of the Domain Admins group. ... > policy which denies them log on access to the servers OU. ...
    (microsoft.public.win2000.group_policy)

Loading