Solved

limits of a local admin

Posted on 2014-02-20
3
366 Views
Last Modified: 2014-03-05
can you help me find the technet document that lists the limitations of a local admin vs domain admin
0
Comment
Question by:25112
3 Comments
 
LVL 5

Author Comment

by:25112
ID: 39874501
mainly need to validate this
"A Local admin cannot make a domain account an admin, only Domain admins can do that"
with a msdn link.

thanks.
0
 
LVL 19

Assisted Solution

by:helpfinder
helpfinder earned 250 total points
ID: 39874518
local admin is admin for a single computer
domai admin is admin for entire domain (for all computers joined into domain)

here you have an article about domain and local admins:
http://technet.microsoft.com/en-us/library/bb726982.aspx
0
 
LVL 16

Accepted Solution

by:
cantoris earned 250 total points
ID: 39875383
Just to expand on the above,
A local administrator has administrative access to JUST that one local machine.  That admin account is created locally on that machine and lives within its Security Accounts Manager database.  It is recognised only on that machine.  It can only appear to work on other machines if those machines have the exact same username and password created on them.

A domain administrator has administrative access to ALL the machines in the domain.  That account lives within Active Directory and is part of the domain admins group.  The domain admins group is automatically made a member of the local administrators group on all machines joined to the domain.  So a domain admin had administrative rights to all machines.

To go from being a local admin to a full domain admin is a massive jump UP, so a local admin cannot promote an account to domain admin for security reasons.
A local admin CAN add a domain account to the LOCAL administrators group of the SAME machine that the admin account lives on.  That admin is only granting administrative access to something he already has full control over.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Do hyper-v and VMware clash 4 82
Windows Restrict installation 11 38
How to remove unneeded words from Notepad? 7 17
SCCM 2012 R2, Rollback KB updates 4 27
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question