• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 190
  • Last Modified:

SuperAD account

I'm looking to create a super user group for my site admin administrators. I need then to be able to restart print spoolers, set up machines, do general admin duties but I don't want them to have domain admin rights, What's the best permissions to give this group or does Windows have a default group just for this? Currently they all have domain access and i know this isnt the correct way to go as i dont want them looking anywhere and everywhere.
0
boomerbostock
Asked:
boomerbostock
  • 2
  • 2
1 Solution
 
Toni UranjekConsultant/TrainerCommented:
Hi boomerbostock,

Members of builtin Print operators group can restart printer spooler. I would additional info about what you mean woth "set up machines" and "general admin duties" to give more precise answer.

HTH

Toni
0
 
boomerbostockAuthor Commented:
join machines to domain
0
 
Toni UranjekConsultant/TrainerCommented:
Any domain user can join 10 machines to domain. But usually you need to Delegate control of an OU for creating computer accounts to this users. Just right click proper OU and follow Delegation of control wizard. Always delegate to group of users -  do not use user accounts. What you need is to allow Full control for Computer account objects (or just creation of these objects).
0
 
boomerbostockAuthor Commented:
but will this allow them to access every file on the network as the have control of the OU?
0
 
LauraEHunterMVPCommented:
If all you want is for users to add/remove workstations to the domain, you only need to delegate the following permissions on Computer objects:

Create selected objects
Delete selected objects
Read all properties
Write all properties

0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now