Read only Admin access to domain servers

I have to give an outside consultant a login account to all my servers so that he can "Look them over" before making a proposal to management.

He will be accessing the domain via PPTP VPN, and then probably doing remote desktop as needed to the servers.

I need to create a read only account for him without re-inventing the wheel in my network and servers.

Thanks in advance
LVL 1
RKoonsAsked:
Who is Participating?
 
Mike KlineConnect With a Mentor Commented:
by default a normal account has read access to most objects in AD.  When you say "look them over" what does that mean.  You can give an account logon locally rights as described here  http://blogs.technet.com/b/activedirectoryua/archive/2010/01/25/allow-logon-locally-to-a-domain-controller.aspx?wa=wsignin1.0

Notice they also mention some of the builtin groups like server operators.  Be careful if you give him elevated rights; you always have to be careful if you go down that route.

Thanks

Mike
0
 
AwinishConnect With a Mentor Commented:
As Mike said, Users in domain by default have read access data in AD, they can't write or change anything in AD, so you can add them in RDP group to allow logon through terminal services & no other membership is required to read the data.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.