Link to home
Start Free TrialLog in
Avatar of WellingtonIS
WellingtonIS

asked on

AD migration

We are merging our child domains into one domain for our corp domain using the quest tool.  My question is we have Enterprise Admins.  However we need only the domain admins to be able to manage the designated OU's that they are assigned.  Otherwise they can't access the Domain Controller in the site.  Is there any way to accomplish this.
Avatar of Govvy
Govvy
Flag of United States of America image

Avatar of Mike Kline
No, you can use the delegation wizard or ACLs to restrict access to an OU; but to fully have rights for a DC you need admin rights which would give them rights to every DC.

Thanks

Mike
Avatar of WellingtonIS
WellingtonIS

ASKER

So there's no way to just designate the OU per site and still have access to the domain controller?
You want them to be able to fully administer the domain controller?
I need them to be able to basically, manage AD, GPO's DNS and reboot the box if necessary
ASKER CERTIFIED SOLUTION
Avatar of Mike Kline
Mike Kline
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
We will check into this and let you know.  thanks for the suggestion.
For QMM what you need is to be a member of the Administrators group in the Domain (under the Built-in OU, or technically CN I think, but whatever).  This will give you a single service account with management abilities in all the domains, at least as far as AD is concerned.

Or, in QMM, you can use different accounts for each domain.  You will want to use separate accounts for workstation (RUM) processing, esp. when you get to the "change domain" functionality.  At this point a single service account tends to create errors - not enough to stop the process, but enough to be annoying.

My corp took away my admin rights on the domain and just gave me enough to do what I needed to do.