admin rights on windows server

can you provide some practical examples of when an employee needs to be granted local admin permissions on a windows server, i.e. what tasks require admin permissions. we are risk assessing all accounts with admin access to the servers and could do with some common tasks on windows servers whereby admin rights are essential
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Muhammad BurhanManager I.T.Commented:
is this Domain Environment or Workgroup ?
pma111Author Commented:
domain env
Sajid Shaik MSystem AdminCommented:
in domain scenarios some sort of the servers like Database, Application servers etc, kind of servers need administrative spillages to Install, Access Admin level privileges it's mandatory to give the local admin rights to the related specific server Administrators.

 i hope you got the point.

all the best
Protecting & Securing Your Critical Data

Considering 93 percent of companies file for bankruptcy within 12 months of a disaster that blocked access to their data for 10 days or more, planning for the worst is just smart business. Learn how Acronis Backup integrates security at every stage

Muhammad BurhanManager I.T.Commented:
there is no need of local/domain admin rights for any ordinary employee except IT related persons because they are responsible for managing backups, event logs, user accounts, scheduling tasks, etc.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Sajid Shaik MSystem AdminCommented:
if the scenario is for users ... in case a user is accessing shared folder on that machine or any shared resources you can give that specific user per mission to full access on that specific resource to share that folder with others

i.e Accounts department can share all files with all department users and manager is having full access right to access delete create folders, sharing permissions on that specific folder or resource.

all the best
Even for those working in IT, make sure you give them two accounts, one to logon as user, and a separate account that has the necessary admin rights which they would use when elevated rights are needed. Teach them not to logon to the PC/Server with that account, but rather just to open the application or whatever it is using it, for example when UAC pops up.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.