Solved

What is the best practice for assigning IT support roles Active Directory administration rights without giving away the "keys to the kingdom"?

Posted on 2011-03-15
2
727 Views
Last Modified: 2012-05-11
Within our 2003 domain I have several IT support specialists that currently have additional domain admin logins. I would like to assign them only the roles they need rather than full domain admin level access. My questions are.
- Friom a security standpoint, what is the best practice?
- Am I limited to the "built in" groups only or can you create your own roles groups?
- Would I benefit from modifying the default domain group policy or using group policy's?
0
Comment
Question by:jffisher
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 
LVL 12

Expert Comment

by:Navdeep
ID: 35138679
Hi,

You can use delegation on OUs to manage but Junior IT Staff. You can Delegate to Groups [domain local/global groups] based on your requirements and then make users the member of those groups.
So simply adding and removing the users from the groups, you can control permissions to them

For more detailed understanding and how to set up please go through this guide

Best Practices for Delegating Active Directory Administration
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=631747a3-79e1-48fa-9730-dae7c0a1d6d3
0
 
LVL 12

Accepted Solution

by:
Navdeep earned 500 total points
ID: 35138778
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
LDAP Setup 6 65
EXCHANGE 2010, EXCHANGE 2013 4 69
2008 R2 Domain Controllers Not Connected for a few hours due to move 6 49
one domain, two sites 3 40
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question