Home All Groups Group Topic Archive Search About

Restrict admins from creating user accounts

Author
26 Mar 2009 2:28 PM
Pierre
We use a user provisioning system and want to disallow all domain admins from
creating user accounts except for a few

any ideas on easily accomplishing this? I did manipulate the rights for a
newly created group and set myself up in it but no success.

-Pierre

Author
26 Mar 2009 2:41 PM
Danny Sanders
What ever you do as an administrator they as administrator can undo.
A written policy signed by all involved is probably your best option.

hth
DDS

Show quoteHide quote
"Pierre" <Pie***@discussions.microsoft.com> wrote in message
news:88376235-4359-4372-97F3-B32295BC9483@microsoft.com...
> We use a user provisioning system and want to disallow all domain admins
> from
> creating user accounts except for a few
>
> any ideas on easily accomplishing this? I did manipulate the rights for a
> newly created group and set myself up in it but no success.
>
> -Pierre
Author
26 Mar 2009 2:45 PM
Richard Mueller [MVP]
"Pierre" <Pie***@discussions.microsoft.com> wrote in message
news:88376235-4359-4372-97F3-B32295BC9483@microsoft.com...
> We use a user provisioning system and want to disallow all domain admins
> from
> creating user accounts except for a few
>
> any ideas on easily accomplishing this? I did manipulate the rights for a
> newly created group and set myself up in it but no success.
>
> -Pierre

You cannot restrict Domain Admins. They must be trusted. The membership
should be limited. Create another group and grant the new group only the
permissions required.

--
Richard Mueller
MVP Directory Services
Hilltop Lab - http://www.rlmueller.net
--
Author
26 Mar 2009 6:21 PM
Pierre
ah huh? thanks

Show quoteHide quote
"Richard Mueller [MVP]" wrote:

>
> "Pierre" <Pie***@discussions.microsoft.com> wrote in message
> news:88376235-4359-4372-97F3-B32295BC9483@microsoft.com...
> > We use a user provisioning system and want to disallow all domain admins
> > from
> > creating user accounts except for a few
> >
> > any ideas on easily accomplishing this? I did manipulate the rights for a
> > newly created group and set myself up in it but no success.
> >
> > -Pierre
>
> You cannot restrict Domain Admins. They must be trusted. The membership
> should be limited. Create another group and grant the new group only the
> permissions required.
>
> --
> Richard Mueller
> MVP Directory Services
> Hilltop Lab - http://www.rlmueller.net
> --
>
>
>