Hello everybody !!
I have two global groups "secAdmin" and "sysAdmin" in my domain. Both are members of "administrators" builtin group.
I would like that only the "secAdmin" members has the rights to manage the accounts of all these groups.
I've tried to remove all the groups and leave only the "secAdmin" group in the security tab, but after a few minutes the user and the groups have the same entries that before (Administrators, DomainAdmins, EnterpriseAdmins, ...)
The only objects that remains with the "secAdmin" privilegies are the OU where these groups are in.
I've tried to uncheck the inheritance option but the system still propagates all the builtin groups permisions.
What can I do ? Is it possible or because they are administrators they will always could do anything in the domain ?
I have two global groups "secAdmin" and "sysAdmin" in my domain. Both are members of "administrators" builtin group.
I would like that only the "secAdmin" members has the rights to manage the accounts of all these groups.
I've tried to remove all the groups and leave only the "secAdmin" group in the security tab, but after a few minutes the user and the groups have the same entries that before (Administrators, DomainAdmins, EnterpriseAdmins, ...)
The only objects that remains with the "secAdmin" privilegies are the OU where these groups are in.
I've tried to uncheck the inheritance option but the system still propagates all the builtin groups permisions.
What can I do ? Is it possible or because they are administrators they will always could do anything in the domain ?