Solved

Administrator Delegation Help

Posted on 2011-02-17
2
195 Views
Last Modified: 2012-05-11
Scenario:
We have 20 Sites globally, 100 Servers (ALL Win 2003) Approx. 3000 Desktop users split between global sites. To manage this we have a service desk tier 1/2/3 and on each site with have what we call low grade administrators (Hands & feet, general daily admin duties etc. etc.) my issue is sorting and an AD Account for these site administrators that allows them to conduct daily duties. In the past Domain Admin rights have been given out all over the place - this has led to serious issues. Can anyone suggest a good solid format for managing this?
0
Comment
Question by:I_T_MAN
2 Comments
 
LVL 3

Expert Comment

by:iamshergill
ID: 34914893
Make them members of below group in A.D.>

-Account Operators
-Backup Operators
-Network Configuration Operatos
-Print Operators

However above given solution is not ultimate because of lake of information. We can also create saperate OUs for each site and delegate administrator to their respective OU, that could be better solution.

If you can provide me list what tasks you want them to do?
0
 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 34914944
I would stay away from the built in groups. These will give more rights than you probably want to give. I would only delegate the rights needed. Do the level 3 people need to logon to the DCs? if they do then you should probbaly give them domain admin, For the other groups they can manage users and computers for their own location if you have the OUs properly seperated. It all depends on what you need these groups to do.



http://www.windowsecurity.com/articles/Built-in-Groups-Delegation.html
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I'm sure that every Windows systems administrator has written, or at least used, a batch or VBS login script at some point in their career, whether it is to map network drives, install printers, or set some user preferences.  No more! With Window…
I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

27 Experts available now in Live!

Get 1:1 Help Now