|
Posted by Steven L Umbach on July 1, 2005, 12:30 am
If you were Registered and logged in, you could reply and use other advanced thread options
You can not really limit a domain admin as they are an administrator for the
domain, for all domain controllers, and all domain computers. What you could
do for non domain controllers is to add their domain user account to the
local administrators group on the domain servers [non domain controllers]
that you wan them to have admin powers on via lusrmgr.msc. Group Policy
Restricted Groups using "member of" can also be used if the number of
servers is substantial. --- Steve
> Hello everyone, I'm just trying to confirm on how to do something.
>
> I'm looking to limit a end user to Domain Admin priv's on a select number
> of
> servers for him to support and nothing else.
>
> I thought there was something I could do through Group Policy - but cannot
> find anything. So my next thought was put them in the Domain Admins group
> and give them logon locally access on the specific servers.
>
> Is there any other way to take care of this?
>
> Mike
>
|