Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

What is the difference between the Administrators group and the Domain Admins group?

Posted on 2010-11-23
2
Medium Priority
?
342 Views
Last Modified: 2012-05-10
What is the difference between the Administrators group and Domain Admins group within Active Directory 2008?
0
Comment
Question by:jdouthit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 8

Assisted Solution

by:ShareefHuddle
ShareefHuddle earned 248 total points
ID: 34201496
Domain Admins

Description:
Members of this group have full control of the domain. By default, this
group is a member of the Administrators group on all domain controllers, all
domain workstations, and all domain member servers at the time they are
joined to the domain.

Administrators

Description:
Members of this group have full control of all domain controllers in the
domain. By default, the Domain Admins and Enterprise Admins groups are
members of the Administrators group.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 252 total points
ID: 34202227
There was also a really great thread on activedir a few years ago   http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/25864/view/topic/Default.aspx

when joe (listmail) and dmitri (internal MS dev) chime in on the same thread then that is a great thread :)

Like they said someone in the builtin Admin group can make themselves a DA so be careful when giving someone either of these elevated rights.
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

664 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question