Minimizing Permission's of Users Who Do Not Need To Be Domain Admins

I need some good advise about the following situation.  I have two users in our company who are currently Domain Admins.  Neither one of these guys should have these rights, but I have not figured out a way to give them what theey need without giving them these priviledges.  Here is what they need to do:

1.  Modify workstations; load software, add and remove from AD.
2.  Access only those servers that pertain to their specific areas of the company - I want to give them access, but not the ability to manipulate the system (i.e. load software, etc).
3.  Change user properties in the AD.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Hi isd503,

1.  Load software/modify workstation - LOCAL admins on the workstations.  Add/Remove from AD, grant their user accounts rights using the Delegation Wizard -

2.  You will need to be more specific here.  you do not want them to install.remove software but they need access - what level of access?  Files?  RDP?  If files, modify share and NTFS permissions to allow.  If they need to reach the server desktop, remove them from local admin and domain admin and add them to the Remote Desktop Users group of the server.

3.  Use the rights delegation wizard -


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.