Account Operator Rights
does have article referencing rights should associated account operators?
i have new domain managing , reason adding personnel account operator group not give them rights reset passwords on standard user accounts. have feeling group may of been manipulated.....
thanks!
hello,
this official description form microsoft account operators:
"members of group can create, modify, , delete accounts users, groups, , computers located in users or computers containers , organizational units in domain, except domain controllers organizational unit. members of group not have permission modify administrators or domain admins groups, nor have permission modify accounts members of groups. members of group can log on locally domain controllers in domain , shut them down. because group has significant power in domain, add users caution."
personal not use account operators group have lot's of permissions. prefer use own created security group , use "delegate control" wizard on ou should have permission work. see great article jorge delegating several admin tasks:
http://blogs.dirteam.com/blogs/jorge/archive/2006/01/05/369.aspx
another important part of account operators is, group protected group adminsdholder comes play, each hour security settings reset automatically:
http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx
best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment