Re: Admin Roles
- From: "Ace Fekay [Microsoft Certified Trainer]" <aceman@xxxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 21 Apr 2009 15:13:13 -0400
"tkutil" <tkutil@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:DD1957B9-D5E9-4CE3-A2F7-EB59AD206D0E@xxxxxxxxxxxxxxxx
I would like to limit admin rights in AD so that low level admins only have
rights to do certain tasks. For one, I would like to have an admin account
that only has rights to add computers to AD and am wondering how other people
are accomplishing dividing up tasks within AD.
The best thing to do is create two user accounts for your administrators. One account is a plain-vanilla, Domain User account they normally logon with, email, etc. The other account is an account that you will delegate or add to a group that has been delegated certain rights in iether an OU or across the domain. When they need to administer tasks, join machines, etc, they will use this account, whether directly logging on or with the RunAs feature.
I hope the following links are helpful with further explaining delegation.
Download details: Best Practices for Delegating Active Directory ...Nov 25, 2003 ... Delegation of administration, a key capability of Active Directory, provides a means to successfully manage an Active Directory environment. ...
http://www.microsoft.com/downloads/details.aspx?familyid=631747a3-79e1-48fa-9730-dae7c0a1d6d3
Implementing Active Directory Delegation of AdministrationSep 13, 2006 ... In this article I will go into the details you need to know on how to implement delegation of administration, as well as some design ideas ...
http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html
--
Ace
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
aceman@xxxxxxxxxxxxxxxxxxxxxxx
For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.
.
- References:
- Admin Roles
- From: tkutil
- Admin Roles
- Prev by Date: Admin Roles
- Next by Date: Inactive user accounts
- Previous by thread: Admin Roles
- Next by thread: Re: Admin Roles
- Index(es):
Relevant Pages
|