Account Operator Rights


does have article referencing rights should associated account operators?

i have new domain managing , reason adding personnel account operator group not give them rights reset passwords on standard user accounts. have feeling group may of been manipulated.....

thanks!

hello,

this official description form microsoft account operators:

"members of group can create, modify, , delete accounts users, groups, , computers located in users or computers containers , organizational units in domain, except domain controllers organizational unit. members of group not have permission modify administrators or domain admins groups, nor have permission modify accounts members of groups. members of group can log on locally domain controllers in domain , shut them down. because group has significant power in domain, add users caution."

personal not use account operators group have lot's of permissions. prefer use own created security group , use "delegate control" wizard on ou should have permission work. see great article jorge delegating several admin tasks:

http://blogs.dirteam.com/blogs/jorge/archive/2006/01/05/369.aspx

another important part of account operators is, group protected group adminsdholder comes play, each hour security settings reset automatically:

http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx


best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file