allow people to logon to DC


hello,

is there way give users admin rights domain controller server without giving user domain admin rights?

we running dual role server dc , sql know not best ppractise company cant afford more servers.

 

so need delegate permissions logon dc

check services

run sql reports etc

 

anyadvice appreciated.

and *** windows 2003 server sp2

 

thanks

junaid

from: http://searchwinit.techtarget.com/tip/0,289483,sid1_gci1167908,00.html

 

allow logon locally user right

there few user rights default domain controllers policy establishes domain controllers might want consider member servers. domain controllers, "administrator" type groups given privilege log on console. helps protect domain controller user logging on in manner. however, since there no gpos active directory modifying default user rights member servers, user allowed log on locally windows 2000 or windows server 2003 member server. includes servers containing hr data , financial data.

 

conclusion:

 

edit default domain controllers policy , allow desired users/groups logon.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file