Remove domain admins from local admins group on specific servers

G

Guest

Hi

I have a few servers in an OU in which I want to assign full control only to
a specific group other than domain admins. If I remove the domain admins
group from the local admins group on these servers :

1. will that prevent all domain admins from logging on to these machines.

2. can they (the domain admins) then seize control of these servers and add
themselves back into the local admins groups (on these machines).

Thanks.
 
D

Danny Sanders

Actually you don't restrict the domain admin you restrict who you add to the
group.

One of the main criteria for being a domain admin is trust. If you can't
trust them they don't need to be a domain admin.

If you could remove them, they as domain admins can undo what ever you can
do as a domain admin.


hth
DDS W 2k MVP MCSE
 
G

Guest

Thanks for your reply, Here is the scenario,

I have delegated full control of an OU under the main domain to a group.
This group has full control over all servers in that OU only but are not
domain admins. This group is also part of the local admins group on all the
servers within that OU only. If one of these users removed the domain admins
group from the local administrators group on one of these servers, will a
domain admin still be able to logon to these servers? Also if they can I
assume they will be able to add themselves back into the local admins group
on the said servers as well.

Thanks
 
D

Danny Sanders

Are we talking about DCs or member servers?

DDS
RA said:
Thanks for your reply, Here is the scenario,

I have delegated full control of an OU under the main domain to a group.
This group has full control over all servers in that OU only but are not
domain admins. This group is also part of the local admins group on all
the
servers within that OU only. If one of these users removed the domain
admins
group from the local administrators group on one of these servers, will a
domain admin still be able to logon to these servers? Also if they can I
assume they will be able to add themselves back into the local admins
group
on the said servers as well.

Thanks
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top