Click here to get back home

AD administrators and domain admins groups

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
AD administrators and domain admins groups OM 04-25-2006
Posted by OM on April 25, 2006, 12:26 pm
Please log in for more thread options
Hi,

What is the main difference, in terms of user privilege, between the
administrators group and domain admins group in active directory?
Accounts in either groups allow me to manage AD. It seems that only the
domain admins group can administer domain workstations and servers.

Thanks

OM

Posted by Joe Richards [MVP] on April 28, 2006, 10:20 am
Please log in for more thread options
Domain Admins is a group with domain affinity, so that means that you can add
Domain Admins to groups on machines anywhere that trusts the domain
(workstations, servers, other domain's, etc). This is why you can manage
workstations, etc in the domain if you have domain admins rights, the domain
admin group was added the local admins groups on the machines.

Other than that, look at the ACLs on AD objects and that will tell you what an
Admin can do versus a Domain Admin or even an Enterprise Admin. The permissions
do vary, however, any one of those groups can easily attain the permissions of
the other on a DC.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



OM wrote:
> Hi,
>
> What is the main difference, in terms of user privilege, between the
> administrators group and domain admins group in active directory?
> Accounts in either groups allow me to manage AD. It seems that only the
> domain admins group can administer domain workstations and servers.
>
> Thanks
>
> OM

Similar ThreadsPosted
Nesting domain groups under local groups March 18, 2007, 3:56 am
log onto a DC for non domain admins November 15, 2005, 9:25 am
Domain admins October 12, 2007, 9:38 am
Restricting Domain Admins June 1, 2005, 5:32 pm
Added to Domain Admins but removed again automatically March 7, 2008, 1:53 pm
Admin shares no longer accessible for users not in domain admins April 22, 2006, 8:09 am
Is It Safe to Deny Administrators Login by Network to Domain Controller? January 13, 2007, 3:00 am
Ability to list groups member of a trusted domain is in July 26, 2006, 12:30 pm
Domain Local Security vs Global Security vs Universal Security Groups October 16, 2006, 1:26 pm
Local admins June 15, 2007, 2:13 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap