Home All Groups Group Topic Archive Search About

How to make sub Domain Admin wit h some restriction

Author
9 Feb 2006 12:19 PM
Dipak
Hi all,

I have windows 2003 domain, i want to make on sub domain admin account with
some restriction like,
- this user can not take ownership the files or folders on which he don't
have rights,
- and this user can not change Administrators user properties.

by adding this user in Domain Admins group it will become sub admin. but how
can i restrict this user for these two conditions?
is anybody help me out...?
thanks in advance

--
Thanks and Regards,

Dipak Patel
Network Administrator
APIMA

Author
9 Feb 2006 3:56 PM
Danny Sanders
> - this user can not take ownership the files or folders on which he don't
> have rights,
> - and this user can not change Administrators user properties.

You can't. If you were to devise a way to do this they as administrator can
undo it.
If you can't trust the administrator they don't need to be an administrator.

hth
DDS W 2k MVP MCSE

Show quoteHide quote
"Dipak" <Di***@discussions.microsoft.com> wrote in message
news:1F163AF2-AB51-4D0B-BD2E-DC7B30CFCA8E@microsoft.com...
> Hi all,
>
> I have windows 2003 domain, i want to make on sub domain admin account
> with
> some restriction like,
> - this user can not take ownership the files or folders on which he don't
> have rights,
> - and this user can not change Administrators user properties.
>
> by adding this user in Domain Admins group it will become sub admin. but
> how
> can i restrict this user for these two conditions?
> is anybody help me out...?
> thanks in advance
>
> --
> Thanks and Regards,
>
> Dipak Patel
> Network Administrator
> APIMA
Author
10 Feb 2006 10:31 AM
Dipak
Thanks for your quick reply Danny
I fully agree with you Danny, fine now is there way that we can we assign
some admin rights to the normal user, like he can do stop/start services,
install softwares, make users groups OU and make Group policy, etc.
but he don't have rights to take ownership and deny rights to change
Administrators properties.

if anybody can help me ...heartily appreciated
--
Thanks and Regards,

Dipak Patel
Network Administrator
APIMA


Show quoteHide quote
"Danny Sanders" wrote:

> > - this user can not take ownership the files or folders on which he don't
> > have rights,
> > - and this user can not change Administrators user properties.
>
> You can't. If you were to devise a way to do this they as administrator can
> undo it.
> If you can't trust the administrator they don't need to be an administrator.
>
> hth
> DDS W 2k MVP MCSE
>
> "Dipak" <Di***@discussions.microsoft.com> wrote in message
> news:1F163AF2-AB51-4D0B-BD2E-DC7B30CFCA8E@microsoft.com...
> > Hi all,
> >
> > I have windows 2003 domain, i want to make on sub domain admin account
> > with
> > some restriction like,
> > - this user can not take ownership the files or folders on which he don't
> > have rights,
> > - and this user can not change Administrators user properties.
> >
> > by adding this user in Domain Admins group it will become sub admin. but
> > how
> > can i restrict this user for these two conditions?
> > is anybody help me out...?
> > thanks in advance
> >
> > --
> > Thanks and Regards,
> >
> > Dipak Patel
> > Network Administrator
> > APIMA
>
>
>
Author
10 Feb 2006 5:39 AM
Cary Shultz
Dipak,

You can not make a Domain Admin "limited".  If I were you I would look into
two things:

1) Delegation of Control
2) hiring trustworthy people!

--
Cary W. Shultz
Roanoke, VA  24012

Show quoteHide quote
"Dipak" <Di***@discussions.microsoft.com> wrote in message
news:1F163AF2-AB51-4D0B-BD2E-DC7B30CFCA8E@microsoft.com...
> Hi all,
>
> I have windows 2003 domain, i want to make on sub domain admin account
> with
> some restriction like,
> - this user can not take ownership the files or folders on which he don't
> have rights,
> - and this user can not change Administrators user properties.
>
> by adding this user in Domain Admins group it will become sub admin. but
> how
> can i restrict this user for these two conditions?
> is anybody help me out...?
> thanks in advance
>
> --
> Thanks and Regards,
>
> Dipak Patel
> Network Administrator
> APIMA