Link to home
Start Free TrialLog in
Avatar of cooljam23
cooljam23

asked on

Can you modify the built-in accounts in windows2000 server

Hi all,

We're wanting to modify the built-in "Account Operators" in AD users and computers.  Is this possible?

We have a new user who's going to be doing low level support stuff and we don't want her to have Domain Admin rights.  

We want her to have the ability to administer user accounts, bring up a remote session to PDC with her user name, connect to client's pc via UNC (\\pc\c$).  I'm thinking that she won't be able to connect to client's pc with her login unless she's domain admin.

If you could please advise.

Thanks
ASKER CERTIFIED SOLUTION
Avatar of Lee W, MVP
Lee W, MVP
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I disagree.  Based on the user's requirements, delegating control through OUs and proper placement of users in such OUs should be sufficient.  If you would prefer NOT accepting my comment as answer, I'll live with that, but the author NEVER responded to the comment and I'm inclined to suggest a PAQ/No Refund before a Delete/Refund.