Word :    Username :           
 

Archived from groups: microsoft.public.win2000.security (More info?)

 

How do I make someone an admin but take away their rights to making changes
within Active Directory? I would like to give a support user the ability to
logon to Domain Controllers to troubleshoot DHCP, DNS and some applications
that run on the server, but I do not want them to have the ability to make
changes to Active Directory (create or delete OUs, delete admins etc).

Thanks
dhodgkins61@comcast.net

Sponsored Links
Register or log in to remove.

Archived from groups: microsoft.public.win2000.security (More info?)

 

Any user can be given the right to logon to a domain controller by
configuring the "logon locally" user right in Domain Controller Security
Policy. Then you can add the user to privileged groups shown in Active
Directory Users and Computers such as DHCP administrators and DnsAdmins. As
far as troubleshooting applications they will have limited ability without
being an administrator but you can test that out to see if it suits your
needs by using privileged groups. Server operators is another group that you
may consider that will give the user more power but the user can then create
and delete shares but will not be able to create/delete OU's or manage
administrator accounts. --- Steve


"DebraH" <DebraH@discussions.microsoft.com> wrote in message
news:E8501DBE-5CD5-4726-9FCF-A1A099473F7B@microsoft.com...
> How do I make someone an admin but take away their rights to making
> changes
> within Active Directory? I would like to give a support user the ability
> to
> logon to Domain Controllers to troubleshoot DHCP, DNS and some
> applications
> that run on the server, but I do not want them to have the ability to make
> changes to Active Directory (create or delete OUs, delete admins etc).
>
> Thanks
> dhodgkins61@comcast.net
>

Reply to Anonymous
Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > create support admin user
Go to:

There are 1035 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them