How best to assignprivilege to IT officer?

Posted on 2006-05-14
Last Modified: 2010-04-18
I run a Windows 2003 server in a small enterprise with about 40 users. I onlyt have one IT technician. I want him to be able to perform some task and not the others.
Specifically I want him to be able to:

Manage AD to add and edit users.
Perform back ups.

I do not want him to be able to change the DHCP and DNS settings.

Please recommend how best to assign him privilege. I tried put him in Domain admin group, but that just gives him all the privilege. I want something more limited.
Question by:SC2002Admin
    LVL 5

    Accepted Solution

    For the editing user accounts part, you first want to create a group called "AD User Management" or something like that. Assign the rights to the group and make this one user a member of that group. Then use the Delegation control wizard to give that groups rights to add/edit/delete user accounts in a certain OU or for the whole domain.

    As for rights to run the backup, the rights do depend on how your backup software plays with rights. With NTBackup, you should be able to make this user a member of the Backup Operators group. With Veritas (Symantec) Backup Exec, I believe it has its own internal authentication in addition to the windows rights.
    LVL 48

    Expert Comment

    Hi SC2002Admin,

    if you dont want him touching DHCP and DNS remove him from those operator groups as well

    Author Comment

    Thanks. I noticed that if the person do not belong to Domain admin group, then he cannot log on the server machine. What to do in this case?

    Should the user be allow to log on the server computer? or is there another (better) way?
    LVL 48

    Expert Comment

    better off would be installing the adminpak on his machine and let him manager from there......

    but if you want him to log on to the server, then you need to edit your default domain controller policy to allow him to logon locally under user rights assignment

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    I have never ceased to be amazed how many problems you can encounter on a fresh install of a Windows operating system.  This is certainly case in point& Unable to complete ANY MSI installation.  This means Windows Updates are failing and I can't …
    This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
    Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now