Dilemma: Domain\DomainUsers in the Domain\Administrators Group


hey all.... inherited pretty messed domain.  scouring ad find domain users (now set primary group new users) member of domain\administrators group.  removed 30 users \domainadministrators group.... i'm little worried happen when remove default group here. 

is legacy thing 2003 or before?  installed 2012 dc wasn't replicated that's fixed i'm trying figure out how clean permissions.  they're pretty in domainusers group... since builtin\users isn't in there don't know if removing domainusers administrators going affect.

lastly since domainusers primary group now... decent way test on users (my thought removing users domain users group) before remove domainusers (everyone) administrators group?

it not legacy , no said domain users added domain administrators.  there reason why these 2 separate groups. saying every ad user domain admin.

this is pure lazy action of unable of unwilling find out needs admin.

consequences of removing it, however, unpredictable don't know may need admin.  remove , let users complaint. then, can find out needed , misusing it.

good luck!


nosh mernacaj, identity management specialist



Windows Server  >  Management



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file