Rights for administering Active Directory and Controllers in one Site


hello, all!

we have active directory domain multiple sites.

following task:

group of users needs administer active directory (domain admins rights only) exception - logons must allowed 2 domain controllers in 1 site. must have full local administrator rights (drivers update, system update, etc) contollers.

buildin\administrators group contains enterprise admins group. however, membership in group give rights every domain controller in domain.


mvp | mcp club lead, moscow

you can try accomplish objective using local group policy , permissions on registry/file system - end unsupported/partially nonfunctional configuration. short answer type of requirement can not satisfied on writeable domain controllers - if want delegate local admin rights domain controllers, need implement rodcs

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file