Rights for administering Active Directory and Controllers in one Site
hello, all!
we have active directory domain multiple sites.
following task:
group of users needs administer active directory (domain admins rights only) exception - logons must allowed 2 domain controllers in 1 site. must have full local administrator rights (drivers update, system update, etc) contollers.
buildin\administrators group contains enterprise admins group. however, membership in group give rights every domain controller in domain.
mvp | mcp club lead, moscow
you can try accomplish objective using local group policy , permissions on registry/file system - end unsupported/partially nonfunctional configuration. short answer type of requirement can not satisfied on writeable domain controllers - if want delegate local admin rights domain controllers, need implement rodcs
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment