Solved

What is the best practice for assigning IT support roles Active Directory administration rights without giving away the "keys to the kingdom"?

Posted on 2011-03-15
2
724 Views
Last Modified: 2012-05-11
Within our 2003 domain I have several IT support specialists that currently have additional domain admin logins. I would like to assign them only the roles they need rather than full domain admin level access. My questions are.
- Friom a security standpoint, what is the best practice?
- Am I limited to the "built in" groups only or can you create your own roles groups?
- Would I benefit from modifying the default domain group policy or using group policy's?
0
Comment
Question by:jffisher
  • 2
2 Comments
 
LVL 12

Expert Comment

by:Navdeep
ID: 35138679
Hi,

You can use delegation on OUs to manage but Junior IT Staff. You can Delegate to Groups [domain local/global groups] based on your requirements and then make users the member of those groups.
So simply adding and removing the users from the groups, you can control permissions to them

For more detailed understanding and how to set up please go through this guide

Best Practices for Delegating Active Directory Administration
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=631747a3-79e1-48fa-9730-dae7c0a1d6d3
0
 
LVL 12

Accepted Solution

by:
Navdeep earned 500 total points
ID: 35138778
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains the steps required to use the default Photos screensaver to display branding/corporate images
A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question