Solved

Administrator Delegation Help

Posted on 2011-02-17
2
197 Views
Last Modified: 2012-05-11
Scenario:
We have 20 Sites globally, 100 Servers (ALL Win 2003) Approx. 3000 Desktop users split between global sites. To manage this we have a service desk tier 1/2/3 and on each site with have what we call low grade administrators (Hands & feet, general daily admin duties etc. etc.) my issue is sorting and an AD Account for these site administrators that allows them to conduct daily duties. In the past Domain Admin rights have been given out all over the place - this has led to serious issues. Can anyone suggest a good solid format for managing this?
0
Comment
Question by:I_T_MAN
2 Comments
 
LVL 3

Expert Comment

by:iamshergill
ID: 34914893
Make them members of below group in A.D.>

-Account Operators
-Backup Operators
-Network Configuration Operatos
-Print Operators

However above given solution is not ultimate because of lake of information. We can also create saperate OUs for each site and delegate administrator to their respective OU, that could be better solution.

If you can provide me list what tasks you want them to do?
0
 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 34914944
I would stay away from the built in groups. These will give more rights than you probably want to give. I would only delegate the rights needed. Do the level 3 people need to logon to the DCs? if they do then you should probbaly give them domain admin, For the other groups they can manage users and computers for their own location if you have the OUs properly seperated. It all depends on what you need these groups to do.



http://www.windowsecurity.com/articles/Built-in-Groups-Delegation.html
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question