SuperAD account

Posted on 2007-07-26
Last Modified: 2010-03-17
I'm looking to create a super user group for my site admin administrators. I need then to be able to restart print spoolers, set up machines, do general admin duties but I don't want them to have domain admin rights, What's the best permissions to give this group or does Windows have a default group just for this? Currently they all have domain access and i know this isnt the correct way to go as i dont want them looking anywhere and everywhere.
Question by:boomerbostock
    LVL 31

    Expert Comment

    by:Toni Uranjek
    Hi boomerbostock,

    Members of builtin Print operators group can restart printer spooler. I would additional info about what you mean woth "set up machines" and "general admin duties" to give more precise answer.



    Author Comment

    join machines to domain
    LVL 31

    Expert Comment

    by:Toni Uranjek
    Any domain user can join 10 machines to domain. But usually you need to Delegate control of an OU for creating computer accounts to this users. Just right click proper OU and follow Delegation of control wizard. Always delegate to group of users -  do not use user accounts. What you need is to allow Full control for Computer account objects (or just creation of these objects).

    Author Comment

    but will this allow them to access every file on the network as the have control of the OU?
    LVL 30

    Accepted Solution

    If all you want is for users to add/remove workstations to the domain, you only need to delegate the following permissions on Computer objects:

    Create selected objects
    Delete selected objects
    Read all properties
    Write all properties


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    What Security Threats Are You Missing?

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Suggested Solutions

    Title # Comments Views Activity
    home folder path for users 4 32
    exchange, scripts 3 34
    Remote install of MSI file 4 18
    Security Permissions Issues 10 22
    I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
    Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

    760 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now