Solved

Domain administrator group add into local administrator group

Posted on 2012-03-24
3
468 Views
Last Modified: 2012-04-23
As I understand , once we join a computer to domain , the domain administrator group will be added into local administrator group .

So, by then the local administrator can act as domain administrator to manage all the domain setting including domain GPO ??  Am I right ??? Please confirm .

If I am right, then the branch office administrator ( local administrator ) can "control" head office domain administrator jobs ???
0
Comment
Question by:kcn
3 Comments
 
LVL 2

Expert Comment

by:Kelden
ID: 37761281
No. The domain administrator is also a local admin. But the local admin is not a domain administrator. So everything is still secure.
0
 
LVL 8

Accepted Solution

by:
Amit Khilnaney earned 250 total points
ID: 37761337
As I understand , once we join a computer to domain , the domain administrator group will be added into local administrator group .

Ans = Yes

So, by then the local administrator can act as domain administrator to manage all the domain setting including domain GPO ??  Am I right ??? Please confirm .

Ans = No, local adminstrator cannot act as domain administrator. For Ex. Try this by adding a domain user to the adminstrators group. Even if you are logged on as "local" adminstrator on computer it will ask to provide domain adminstrator credentials.

If I am right, then the branch office administrator ( local administrator ) can "control" head office domain administrator jobs ???

Ans = Incorrect the bracnh office local admin cannot control head office domain administrator jobs
0
 
LVL 77

Assisted Solution

by:arnold
arnold earned 250 total points
ID: 37762254
Levels of access from lowest to highest
Limited local user
Limited domain user
Local power user
Domain power user
Local admin
Domain admin

Domain based groups have higher ranking because they are to limited to a single machine even though they have the same level rights on each machine.
There are other domain based groups the provide different access lever, rights, but are not mortar to the comparison here dealing with domain versus equivalent local accounts.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is my 3rd article on SCCM in recent weeks, the 1st (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/A_4466-A-beginners-guide-to-installing-SCCM2007-on-Windows-2008-R2-Server.html) dealing with installat…
Ever notice how you can't use a new drive in Windows without having Windows assigning a Disk Signature?  Ever have a signature collision problem (especially with Virtual Machines?)  This article is intended to help you understand what's going on and…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question