We help IT Professionals succeed at work.

"Domain Controller Builtin\Administrator" VS "Domain Administrator" - whats the difference

detox1978
detox1978 asked
on
Medium Priority
1,014 Views
Last Modified: 2008-02-07
Hi All,


I work in a single domain enviroment.


What's the difference between the builting Domain Controller "Builtin\Administrator" and the "Domain Administrator" group.


The reason i ask is we have a lot of users in "Builtin\Administrator" group on the DC


Thanks
Comment
Watch Question

EXACLY where are you seeing the builtin\administrator group?
i'm not sure where the "domain administrator" group you are talking about comes from either, b/c in my domain all of the built in groups are called "xxx Admins" without the word administrator spelled out.  This domain has been upgraded from NT4, to 2000 to 2003 so that might be why though.

Solutions Architect
CERTIFIED EXPERT
Commented:
For a file server the built in Administrators group has all the admin permissions and by default when it is added to the domain, Domain Admins gets added to the Local Adminstrators.

For the case of AD, the Built in Administrators group pretty much all the local permission to AD and by default the Domain Admins group is a member of the built in administrators.  Domain Admins\enterprise admins\Schema Admins are given addition permissions to the directory that being a member of the built in administrators won't give you.  Also being in Domain Admins by default gives you admin access to all member machines (desktops\servers).

So essentially,

Members of the built in adminstrators, they can do almost anything to AD user/group/computer objects, But they won't have access to the file servers or desktops.  However, they can add themselves to the Domain Admins group and have access to all computers in the domain.



Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
if you are seeing the 'builting\administrators" on NTFS permissions (the security tab on the properties of a file/folder" then that is the LOCAL admin group.  The domain admin group is a DOMAIN administrator group.  these are two completely different groups.  

>>The reason i ask is we have a lot of users in "Builtin\Administrator" group on the DC
this is what confuses me and why i asked that you explain EXACLY where you saw this.  B/C on a DC, there is no such thing as a local group.

Author

Commented:
Thanks Pber, that was what i thought, but wanted it confirmed.


mikeleebrla, mikeleebrla, its in the "Builtin" OU.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.