Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

How do I creat limited domain admin account

Posted on 2012-09-04
13
Medium Priority
?
2,265 Views
Last Modified: 2012-09-04
We have a new IT personnel. I want this person to have domaain admin rights with limited capability.
Goals:
I want this limited domain admin to add computers.
I want this limited domain admin to add/remove programs.
I do not want this admin to be able to use RDP or access any of my servers.

Please advise.
0
Comment
Question by:tomfontanilla
13 Comments
 
LVL 23

Expert Comment

by:Stelian Stan
ID: 38364324
0
 
LVL 10

Expert Comment

by:remmett70
ID: 38364339
I would leave this new person as a simple domain user.

Create a group or add the user to an existing group that you can add to the local Admin group of Computers (not servers).  which would provide the ability to add programs to workstations.

Create or modify GPO to give the user permission to add computers to the domain.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 38364377
See my answer here about delegating rights to add machines to the domain

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/Q_26574210.html

Do you want the person/group to be able to add remove programs to users workstations.   If that is the case use restricted groups and just give them admin rights to your workstations and nothing else. More on restricted groups here   http://www.frickelsoft.net/blog/?p=13

Thanks

Mike
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 

Author Comment

by:tomfontanilla
ID: 38364423
Thank you all for your response.

mkline71,

SO using, I have to create an OU. Under this OU create a group called "helpdesk".
Under this group, I have to add GP. On the GPO, I have to delegate rights.
 is this correct?
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 38364451
Do you have a workstations OU? the GPO would be linked to that OU (the restricted groups GPO).  

Delegating rights to join machines can be done at the domain level.

Thanks

Mike
0
 

Author Comment

by:tomfontanilla
ID: 38364472
Yes I do. But as we grow, we may need to keep hiring an IT personnel within 2 years, atleast 2 to 3 person. So i am looking for long term.
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 2000 total points
ID: 38364486
So that is why you delegate it to a group, call it "workstations admins" then when the new person comes you just add them to that group and they have the delegated rights.

Thanks

Mike
0
 

Author Comment

by:tomfontanilla
ID: 38364511
OK. I will try this.
0
 

Author Comment

by:tomfontanilla
ID: 38364673
mkline71,

OK. It looks like it's working. However, I did encounter some issues. I cannot add user on the local machine. Thoughts.

Thank you for your help.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 38364730
Did you use restricted groups to do that?
0
 

Author Comment

by:tomfontanilla
ID: 38365031
Got it. It's working. Change the secpol
0
 

Author Closing Comment

by:tomfontanilla
ID: 38365037
Great responds time and answer.
0

Featured Post

Become an Android App Developer

Ready to kick start your career in 2018? Learn how to build an Android app in January’s Course of the Month and open the door to new opportunities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

581 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question