Link to home
Start Free TrialLog in
Avatar of sjones925
sjones925

asked on

Designing permissions for Admins in Active Directory

I am looking to create permissions for some NT Admins to Active Directory and for management of member servers.  They will need limited functionality in AD that I believe will be handled mostly by Account Operators.
I also need them to be able to log into all servers in the domain.  At this point we don't want to give them the full permissions given by Domain Admins or Administrators.  I'm looking for ideas of how best to accomplish this. Can I delegate "log on locally" to a servers OU possibly to accomplish this?  Any ideas or best practices are welcomed.
ASKER CERTIFIED SOLUTION
Avatar of ShimonYK
ShimonYK

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial