Re: Domain Admin rights



steve wrote:
Currently whenever I need to perform modifications on my servers
(e.g. add user account, search for files, set permissions etc.) I log
in locally or via RDP using the domain admin account and then log out
when finished. No other user account belongs to the domain admins
group. As it is only me and another user that who will ever be
performing these kind of actions, is it OK to continue to use this
setup or should I grant us both domain admin rights so we can make
these changes from our console? It is a relatively small domain (~100
users) with a small number of servers running windows 2003.

Basically my question is "should standard user accounts ever be added
to the domain admins group"?

I'd love to hear of alternative setups etc.


No, you shouldn't add your normal user account to domain admins. You can
however install the adminpak on your local machine. Then you can logon as a
domain admin and run the administration consoles on your local machine then
logoff when finished. You can also setup a manager account and use the
delegate control wizard to allow that account to do specific things like add
users etc.

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/ctrlwiz.mspx

--
Kerry
MS-MVP Windows - Shell/User


.



Relevant Pages

  • Re: Prevent some Domain Admin Account from creating USERS, Groups, OUs
    ... if that person is not a DA or shouldn't be, delegate. ... User Account, Security Groups, OUs and modifying those object ... These Domain Admin Account handle administrative tasks over Domain ... Roles, Promote New Domain Controller, Configure AD Replication, DNS ...
    (microsoft.public.win2000.active_directory)
  • Re: Prevent some Domain Admin Account from creating USERS, Groups, OUs
    ... This posting is provided "AS IS" with no warranties, ... User Account, Security Groups, OUs and modifying those object ... These Domain Admin Account handle administrative tasks over Domain ... Roles, Promote New Domain Controller, Configure AD Replication, DNS ...
    (microsoft.public.win2000.active_directory)
  • Re: How to prevent some specific Domain Admin Accounts from creating USERS, Groups, OUs
    ... This posting is provided "AS IS" with no warranties, ... User Account, Security Groups, OUs and modifying those object ... These Domain Admin Account handle administrative tasks over Domain ... Roles, Promote New Domain Controller, Configure AD Replication, DNS ...
    (microsoft.public.windows.server.general)
  • Re: Re: RE: SCW --> GPO
    ... To enable gpedit logging, set the following key ... I'll try to research the scw log. ... The user account is a Domain Admin, and have tried with aother domain ...
    (microsoft.public.windows.group_policy)
  • Re: Admnistrator, Administrators & Admin rights question?
    ... I want to setup this particular system for a user and restrict some of the ... Having the Administrator account 'hidden' from the user at the normal login ... prompt is ideal - that way only the normal user account will show up. ... Having just installed a new XP Pro install on a notebook I have a question ...
    (microsoft.public.windowsxp.general)

Loading