Re: True difference between Domain Admin grp and Administrators Group



The answer is: They lose nothing. The domain admin group
is a member of the domain "administrator" group by default.
I can think of one main difference off the top of my head:
The domain admin group not only has local administrator
access to all DCs like the domain "administrator" group but
it also has local "administrative" access to all domain members
as well. When a computer joins the domain the domain admin
group is automatically added to the local "administrators" group.
The domain "administrators" group is a local group and the
"domain admin" group is a global group. Below is the official
explaination from Windows Server 2003 Help and Support:


Domain Admins

Description:
Members of this group have full control of the domain. By default, this
group is a member of the Administrators group on all domain controllers, all
domain workstations, and all domain member servers at the time they are
joined to the domain. By default, the Administrator account is a member of
this group. Because the group has full control in the domain, add users with
caution.

Default User Rights:

Access this computer from the network; Adjust memory quotas for a process;
Back up files and directories; Bypass traverse checking; Change the system
time; Create a pagefile; Debug programs; Enable computer and user accounts
to be trusted for delegation; Force a shutdown from a remote system;
Increase scheduling priority; Load and unload device drivers; Allow log on
locally; Manage auditing and security log; Modify firmware environment
values; Profile single process; Profile system performance; Remove computer
from docking station; Restore files and directories; Shut down the system;
Take ownership of files or other objects.


Administrators
Description:
Members of this group have full control of all domain controllers in the
domain. By default, the Domain Admins and Enterprise Admins groups are
members of the Administrators group. The Administrator account is also a
default member. Because this group has full control in the domain, add users
with caution.

Default User rights:
Access this computer from the network; Adjust memory quotas for a process;
Back up files and directories; Bypass traverse checking; Change the system
time; Create a pagefile; Debug programs; Enable computer and user accounts
to be trusted for delegation; Force a shutdown from a remote system;
Increase scheduling priority; Load and unload device drivers; Allow log on
locally; Manage auditing and security log; Modify firmware environment
values; Profile single process; Profile system performance; Remove computer
from docking station; Restore files and directories; Shut down the system;
Take ownership of files or other objects.



"Rob" <Rob@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:
> All.
>
> I am trying to come up with a true reason adn difference between the
> Administrators group and the Domain Admins group. OTHER THAN... the fact
that
> Administrators have local access and control. If in the Domain Admins
what
> else do they lose??
>
> Also.. What the heirarchy of all teh Built in user groups..
>
> Thanks
>
> r


.



Relevant Pages

  • RE: How to prevent some specific Domain Admin Accounts from creating U
    ... kamleshqwalani is incorrect - if you add a user to the Built-In Administrators group on a domain controller, that user becomes an administrator on all domain controllers in your domain, and by extension a Domain Admin. ... (kamleshqwalani is correct about local Administrator membership on workstations and member servers, ... So making a user a Domain Admin will automatically profer certain rights to domain-joined workstations and servers that BUILTIN\Administrators does not...but at the end of the day a member of BUILTIN\Administrators on a DC still has the effective rights of a Domain Admin, and so a determined user could figure out how to grant themselves whatever rights they don't have by default on workstations/member servers. ...
    (microsoft.public.windows.server.active_directory)
  • RE: software to control domain administrators
    ... these so-called controls on the admin. ... what would you do when you need that level of control. ... admin changed the domain admin password when he or she found out that they ... software to control domain administrators ...
    (Security-Basics)
  • "Take Ownership" gives to Group
    ... I'm trying to take ownership of a directory and the result ... is ownership is given to the "Administrators" group (a group ... I am member of). ... control of this directory and have the "Take Ownership" ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Administrator cant change security
    ... administrators group on the domain member can configure permissions on any ... computers can not reliably contact a domain controller. ... I'm signing on as Administrator on a second Windows 2003 server that is ...
    (microsoft.public.windows.server.security)
  • Re: Security groups being removed
    ... be the expected behavior because of the AdminSDHolder thread on the DC ... This object is used to control the permissions of user accounts that are ... members of the built-in Administrators or Domain Administrators groups. ... a user account is a member of one of these administrative groups because ...
    (microsoft.public.windows.server.sbs)