Home All Groups Group Topic Archive Search About

Admin rights for 1 DC in a Domain with a few DC's

Author
8 Feb 2006 4:10 PM
Tomato_DeluXe
Hello@all

In our company we have several DC all together in one Domain.
The IT Team in our Headquarter is responsible for the DC administration.
So i am a local admin, responsible for 2 offices, each one has a DC.

Sometimes i need admin right on a DC to start a Programm or so, but the IT
guys in our Headquarter say that there is NO way to get Adminrights on only 2
DC.

For Adminrights on a DC i have to be member of the DOMAIN ADMIN group.
They will not put me in this Domain admin group. Only 3 person can work with
such rights, i am not one of them they said.

is it possible to create an account who has only local admin rights on 2 Dc
in a domain and not on every dc in the hole domain ??

thanx a lot for some answers :-)

--
Save the forest.....eat more beavers

Author
8 Feb 2006 4:30 PM
Tomasz Onyszko
Tomato_DeluXe wrote:
Show quoteHide quote
> Hello@all
>
> In our company we have several DC all together in one Domain.
> The IT Team in our Headquarter is responsible for the DC administration.
> So i am a local admin, responsible for 2 offices, each one has a DC.
>
> Sometimes i need admin right on a DC to start a Programm or so, but the IT
> guys in our Headquarter say that there is NO way to get Adminrights on only 2
> DC.
>
> For Adminrights on a DC i have to be member of the DOMAIN ADMIN group.
> They will not put me in this Domain admin group. Only 3 person can work with
> such rights, i am not one of them they said.
>
> is it possible to create an account who has only local admin rights on 2 Dc
> in a domain and not on every dc in the hole domain ??
>
> thanx a lot for some answers :-)

Not now, it's in longhorn time frame - right now to be administrator on
DC You have to be in domain admin group.

If some application requires administrative right to be started the best
approach is to work with DA group from HQ to determine why it needs
admin rights (in most cases it is because of NTFS and registry
permissions) and configure permissions in the way which will allow You
to run application.