Rights for administering Active Directory and Controllers in one Site


hello, all!

we have active directory domain multiple sites.

following task:

group of users needs administer active directory (domain admins rights only) exception - logons must allowed 2 domain controllers in 1 site. must have full local administrator rights (drivers update, system update, etc) contollers.

buildin\administrators group contains enterprise admins group. however, membership in group give rights every domain controller in domain.


mvp | mcp club lead, moscow

you can try accomplish objective using local group policy , permissions on registry/file system - end unsupported/partially nonfunctional configuration. short answer type of requirement can not satisfied on writeable domain controllers - if want delegate local admin rights domain controllers, need implement rodcs

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

directory stack

After enabling Windows Server 2012 R2 DHCP Failover Getting Packet dropped because of Client ID hash mismatch

WMI Repository 4GB limit - Win 2003 Ent Question