Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251

Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251

Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
Giving admins Local Admin to DC's not Domain Admins
Giving admins Local Admin to DC's not Domain Admins

Giving admins Local Admin to DC's not Domain Admins

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Giving admins Local Admin to DC's not Domain Admins Brodieman 08-15-2008
Posted by =?Utf-8?B?QnJvZGllbWFu?= on August 15, 2008, 4:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


Hi guys

I have a requirement to be able to let certain sets of administrators the
ability to login to domain controllers with out permissions over the whole
domain.

Althought I can give the users PowerUser or LocalLogon rights via making a
domain security group a member of the PowerUser or LocalLogon group there
does not appear to be a local admin group on DCs.

Can you with Server 2003 give a user just local admin to a DC without DA
rights???

Posted by S. Pidgorny on August 15, 2008, 9:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


No. You can grant permission to log on locally (group policy - user righs
assignments) and via remote desktop, and other rights and permissions, but
there's no such thing as local administrators on DCs.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Hi guys
>
> I have a requirement to be able to let certain sets of administrators the
> ability to login to domain controllers with out permissions over the whole
> domain.
>
> Althought I can give the users PowerUser or LocalLogon rights via making a
> domain security group a member of the PowerUser or LocalLogon group there
> does not appear to be a local admin group on DCs.
>
> Can you with Server 2003 give a user just local admin to a DC without DA
> rights???



Posted by =?Utf-8?B?QnJvZGllbWFu?= on August 16, 2008, 5:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Thanks you for that, i guess that might be the case.

"S. Pidgorny <MVP>" wrote:

> No. You can grant permission to log on locally (group policy - user righs
> assignments) and via remote desktop, and other rights and permissions, but
> there's no such thing as local administrators on DCs.
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
> > Hi guys
> >
> > I have a requirement to be able to let certain sets of administrators the
> > ability to login to domain controllers with out permissions over the whole
> > domain.
> >
> > Althought I can give the users PowerUser or LocalLogon rights via making a
> > domain security group a member of the PowerUser or LocalLogon group there
> > does not appear to be a local admin group on DCs.
> >
> > Can you with Server 2003 give a user just local admin to a DC without DA
> > rights???
>
>
>

Posted by Shenan Stanley on August 16, 2008, 5:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Brodieman wrote:
> I have a requirement to be able to let certain sets of
> administrators the ability to login to domain controllers with
> out permissions over the whole domain.
>
> Althought I can give the users PowerUser or LocalLogon rights via
> making a domain security group a member of the PowerUser or
> LocalLogon group there does not appear to be a local admin group
> on DCs.
>
> Can you with Server 2003 give a user just local admin to a DC
> without DA rights???

S. Pidgorny <MVP> wrote:
> No. You can grant permission to log on locally (group policy -
> user righs assignments) and via remote desktop, and other rights
> and permissions, but there's no such thing as local administrators
> on DCs.

Brodieman wrote:
> Thanks you for that, i guess that might be the case.


No need for guessing.
Domain Controllers do not have local accounts.

http://windowsitpro.com/article/articleid/76765/jsi-tip-5461-what-happens-to-the-local-user-accounts-when-i-promote-a-server-to-a-domain-controller.html

http://techrepublic.com.com/5208-7343-0.html?forumID=102&threadID=268861&start=0

Good luck!

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



Posted by Roger Abell [MVP] on August 19, 2008, 11:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


> Brodieman wrote:
>> I have a requirement to be able to let certain sets of
>> administrators the ability to login to domain controllers with
>> out permissions over the whole domain.
>>
>> Althought I can give the users PowerUser or LocalLogon rights via
>> making a domain security group a member of the PowerUser or
>> LocalLogon group there does not appear to be a local admin group
>> on DCs.
>>
>> Can you with Server 2003 give a user just local admin to a DC
>> without DA rights???
>
> S. Pidgorny <MVP> wrote:
>> No. You can grant permission to log on locally (group policy -
>> user righs assignments) and via remote desktop, and other rights
>> and permissions, but there's no such thing as local administrators
>> on DCs.
>
> Brodieman wrote:
>> Thanks you for that, i guess that might be the case.
>
>
> No need for guessing.
> Domain Controllers do not have local accounts.
>
>
http://windowsitpro.com/article/articleid/76765/jsi-tip-5461-what-happens-to-the-local-user-accounts-when-i-promote-a-server-to-a-domain-controller.html
>
>
http://techrepublic.com.com/5208-7343-0.html?forumID=102&threadID=268861&start=0
>
> Good luck!
>
> --
> Shenan Stanley
> MS-MVP
> --

While that is true, that there is no local SAM of account during normal
DC operations, the requirement poster stated, to allow them to be
admins on the DCs without being admins over active directory is
satisfied by the Administrators group of the domain. Accounts in
that group are pretty much just domain users that also have admin
(i.e. server admin) rights when logged into a DC. They do not have
extra permissions in AD or on joined machines.

Roger



Similar ThreadsPosted
Domain Admins Not Fully In Local Administrators December 30, 2008, 11:11 am
users and local Admins November 5, 2006, 5:27 am
Only domain admins can install? November 11, 2008, 3:10 pm
What is the best way to restrict access to Domain Admins on certain folders? March 19, 2008, 10:31 am
How do I manage local admin accounts without a domain or ADS? November 16, 2005, 6:22 pm
Admins with limited rights July 2, 2007, 8:04 am
Security: Network Admins vs. SQL Programmers May 23, 2006, 3:47 pm
Giving access to a share folder in domain A to users in Domain B May 17, 2007, 2:22 pm
Need security advice from Admins at Software Development companies October 18, 2005, 11:29 am
SmartCard Login+certificate to to AD & admins using Remote Control December 15, 2005, 10:40 pm

The site map in XML format XML site map

Contact Us | Privacy Policy