Can someone help me figure out how to give someone admin rights to a Domain Controller (and thereby do tasks such as defrag) but not have access to Active Directory?
Hmm. I think you could be stuffed. I may be wrong - after all a bottle of red wine in the garden never helps...but I think that cos a DC is a DC then it doesn't have any local security options.
AD is so much a part of a DC that you cannot split it out.
M.
Hollingside Technologies, Making Technology work for you.
Oh! here is a thing - in the OU (organisational units) in AD you can delegate authority to various users..can you also say who can and cannot manage the users? If so then you are away......just create a user that has admin rights, but deny him mangerial rights over the users at a root level...or do it the otherway around - create a new group of users who do have rights over the OUs and don't assign Mr Defrag to that group.
Does that make any sense?
I'll re-read all this again in the office tomorrow and wonder what I was on!
Hollingside Technologies, Making Technology work for you.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.