Dilemma: Domain\DomainUsers in the Domain\Administrators Group
hey all.... inherited pretty messed domain. scouring ad find domain users (now set primary group new users) member of domain\administrators group. removed 30 users \domainadministrators group.... i'm little worried happen when remove default group here.
is legacy thing 2003 or before? installed 2012 dc wasn't replicated that's fixed i'm trying figure out how clean permissions. they're pretty in domainusers group... since builtin\users isn't in there don't know if removing domainusers administrators going affect.
lastly since domainusers primary group now... decent way test on users (my thought removing users domain users group) before remove domainusers (everyone) administrators group?
it not legacy , no said domain users added domain administrators. there reason why these 2 separate groups. saying every ad user domain admin.
this is pure lazy action of unable of unwilling find out needs admin.
consequences of removing it, however, unpredictable don't know may need admin. remove , let users complaint. then, can find out needed , misusing it.
good luck!
nosh mernacaj, identity management specialist
Windows Server > Management
Comments
Post a Comment