Solved

Logging onto a Windows 2003 Domain Controller

Posted on 2011-03-14
3
299 Views
Last Modified: 2012-05-11

I've always been a Domain Admin and or Administrator of the domain, so logging on to setup or resolve a printer issue hasn't been an issue.  

We have a new desktop person and we want them to be able to logon and work on printers.  Seems like this may be a challenge and that having the printers on the DC is an issue as only Domain Admins or Administrators are able to logon. Is that correct?  If so, any suggestions on how to resolve this?

Thanks,
RP
0
Comment
Question by:rotarypwr
3 Comments
 
LVL 3

Expert Comment

by:Vinamilk1001
ID: 35130909
Hello ,

Try to put this person on the AD built-in group named "Server operators " and "Print operators , it delegate right to person make action on DC without to have the privilege to modify AD .

Second option is to have a dedicated Print Server or migrate the printers on another servers.
 
Rgds.
0
 
LVL 34

Accepted Solution

by:
Seth Simmons earned 500 total points
ID: 35130943
to allow an ordinary user to logon to a domain controller, you change the domain controller security policy.  if it's at the console, add that user to 'allow logon locally' or for rdp access 'allow logon through terminal services'
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 35130978
You have identified the problem yourself. You "Should" be moving the printer role off the AD and onto a member server.

Alowing ANYBODY except a domain admin access to your domain controllers is a very risky business.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The 21st century solution to antiquated pagers.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question