AD Domain Administrator Priv/rights

AD Domain Administrator Priv/rights

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
AD Domain Administrator Priv/rights Marc Johnson 09-27-2005
Posted by =?Utf-8?B?TWFyYyBKb2huc29u?= on September 27, 2005, 8:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello:

I need to know if there is a way to give admins the rights they need to
the domain/files and folders on DC's and servers without granting them GOD
rights? Is there a best practice out there or has anyone done it. Basically
we don't want to put any Admin into the Domain Admin Group, instead create a
group that gives them the folder/file, and disk rights they need to do the
job of a network administrator. Is there a case study or anything of that
nature that will help us define those rights and privs? Any help would be
appreciated, thanks.

Posted by Steven L Umbach on September 27, 2005, 7:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If all you want to do is to manage access to files/folders then modify share
and ntfs permissions for the users that need access which could be regular
domain users assuming you are not talking about the administrative shares
such as C$. If you want the user to install applications on a domain
controller then they would need to be an administrator for the domain unless
the application is a .msi package that can be published via Group Policy
Software Installation. If you could be more specific on exactly what you
need these users to do someone on this newsgroup could probably be of
lp. --- Steve


> Hello:
>
> I need to know if there is a way to give admins the rights they need
> to
> the domain/files and folders on DC's and servers without granting them GOD
> rights? Is there a best practice out there or has anyone done it.
> Basically
> we don't want to put any Admin into the Domain Admin Group, instead create
> a
> group that gives them the folder/file, and disk rights they need to do the
> job of a network administrator. Is there a case study or anything of that
> nature that will help us define those rights and privs? Any help would be
> appreciated, thanks.



Similar ThreadsPosted
Domain user is seen as domain administrator? May 30, 2006, 8:30 am
should i have to rename administrator on domain server. April 24, 2006, 2:46 pm
Domain User -> Configure as Local Administrator December 10, 2005, 12:51 am
Domain Administrator cannot logon to SBS 2003 LOCALLY January 24, 2006, 6:28 am
Domain users members of local administrator March 14, 2006, 3:00 am
Problem with Domain Admin becoming Administrator (builtin) April 11, 2006, 10:08 am
Built-in Administrator acct. for Domain be password never expires? October 2, 2006, 3:01 pm
domain users added to local administrators cannot use the IPSEC certification of administrator? February 9, 2006, 12:26 am
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
Giving access to a share folder in domain A to users in Domain B May 17, 2007, 2:22 pm

The site map in XML format XML site map

Contact Us | Privacy Policy