Active Directory site administrators?

Posted on 2006-04-17
Last Modified: 2010-04-18
Hi folks,

I'm working on a domain migration from like 7 domains to 1. There's no rhyme or reason to having the 7 domains and now preparing for auditing, we are trying to migrate into a single one. However I am curious about one thing... if I have different sites in my AD structure (geographic sites under Sites and Services), is there a way to assign an administrator to that specific site? I don't want to give them Domain Admin rights, but I don't seem to see anything that looks like a "Site Administrtor" under the default groups. This way I can delegate responsibilities to certain individuals to manage their geographic spectrum though I still have the default domain rights to filter down to them if need be. This way they are somewhat autonomous and also connected to the rest of the AD users.

Much appreciated for any information.
Question by:overworkedops
    1 Comment
    LVL 82

    Accepted Solution

    Create different OUs, and put the accounts you want to be controlled by other people into these OUs, then delegate the control over these OUs.
    Do NOT delegate control to individual user accounts; create dedicated groups for that.
    Check these links for details:

    HOW TO: Delegate Administrative Authority in Windows 2000

    HOW TO: Create and Edit a Taskpad View in a Saved MMC Console in Windows 2000

    Default Security Concerns in Active Directory Delegation

    Delegate Control Wizard Cannot Be Used to Remove Groups or Users

    Administrative Tool Menu Is Sensitive to User's Permissions

    Active Directory Database Size and Delegation Access Rights

    How To Delegate the Unlock Account Right

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Join & Write a Comment

    So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
    On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!
    how to add IIS SMTP to handle application/Scanner relays into office 365.

    755 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now