Re: local admin permissions on DC



Hi,

If this is something you really want to do (!), you will have to give this
user "Log on locally" and "Allow logon through Terminal Services" on Default
Domain Controller Security policy. ("Allow logon through Terminal Services"
is only necessary if the user will be using RDP to logon to this domain
controller).

--
Mike
Microsoft MVP - Windows Security

"jremmc" <jremmc@xxxxxxxxxxxxxx> wrote in message
news:OOxFznfkFHA.1480@xxxxxxxxxxxxxxxxxxxxxxx
> Hi All,
>
> I remember a post about this a while ago but can't find -- how to give a
> person permissions to one specific DC only and not AD, DNS, WINS -- to be
> able to monitor and fix OS (when necessary, knock wood, good now :-)).
> Can't find references to this kind of how-to in docs.
>
> I know I have to add the person to DC Default Policy log on interactively
> for him to use remote desktop, btw.
>
> This is for monitoring a branch office DC -- the IT person was the NT
> domain admin there and we just migrated the office, he is not familiar
> enough yet with AD/WS2K3, want to limit him to just the DC as if it was
> not a DC. (hope that makes sense)
>
> Thanks!
>
>
>
>


.



Relevant Pages

  • Re: Permissions to Log on to Domain Controller
    ... You can view and modify who can logon to a domain controller by looking at the "logon ... locally" user right in Domain Controller Security Policy security settings/local ...
    (microsoft.public.win2000.general)
  • Re: Security policy locking out winlogon for user.
    ... computer settings rather than user settings because the user will never ... I would apply "Deny Logon Locally" found in [Computer ... and Domain controller security policy. ...
    (microsoft.public.windows.group_policy)
  • Re: Urgent Policy question
    ... Yea, i accidently put it in the Deny logon on locally, not paying attention. ... > share to restore default user rights for Domain Controller Security Policy. ... > administrator or entering domain administrator credentials when you try to ...
    (microsoft.public.win2000.group_policy)
  • Re: User cant access the server
    ... In Domain Controller Security Policy make sure that auditing of logon events ... and privilege use is enabled for failure - at least temporarily. ... computer from the network user right for domain controllers which by default ...
    (microsoft.public.win2000.security)
  • Re: Local Policy
    ... > In Administrative Tools, go to Domain Controller Security Policy. ... and then click User Rights Assignment. ...
    (microsoft.public.win2000.active_directory)