Solved

Accessing 2003 Domain Controller without being a Domain Admin

Posted on 2006-07-12
4
368 Views
Last Modified: 2010-04-18
Hoping someone can help me. I have a requirement for a couple of staff to RDP or direct logon to a Windows2003 Domain Controller, but they are not members of the Domain Admins group.

Where on the server can I add them to allow local access and RDP access, with the same rights if it had a local Administrators account.

Thanks
0
Comment
Question by:Nero_Wolfe
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:valrog
ID: 17090428
Why would you give non-Admins rights to a DC?  Do you know the havoc they could cause?  

Anyhow,  I think you may need to install terminal services.
0
 
LVL 1

Author Comment

by:Nero_Wolfe
ID: 17091547
Because, to satisfy auditors there can only be a limited amount of Domain Admins, which is myself and the backup account.  However i need the it staff to be able to login to the server at the console or via RDP.  I know it can be done, as i've had it done before - something to do with local policies - but I can't remember how to do it.

0
 
LVL 3

Accepted Solution

by:
valrog earned 500 total points
ID: 17092848
Open the Group Policy Management Console (gpmc.msc)

Edit the "Default Domain Controllers Policy"

Computer Configuration
 Windows Settings
  Security Settings
   Local Policies
    User Rights Assignments
    --- Allow logon locally
    --- Allow logon through terminal services


Sorry it took so long, I was working on the same problem also (Test Enviroment)
0
 
LVL 1

Author Comment

by:Nero_Wolfe
ID: 17093539
Thanks - much appreciated.  I thought it was in Policies somewhere, but just couldn't lay my hand to the location.

Thanks again.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now