G
Guest
Situation: a forest consisting of a root domain and a child domain, all with
Win2003.
Is it possible to prevent admins from a child domain to do some tasks or
replace ownership to their own in the child domain?
Simple example: I create a folder on a child domain's DC and want to leave
access to only Enterprise Admins from root domain. I set all the perms, take
ownership to Ent. admins., but child domain's admin still easily can re-take
ownership and change ACL.
Is it possible to solve?
Thanks,
Gera
Win2003.
Is it possible to prevent admins from a child domain to do some tasks or
replace ownership to their own in the child domain?
Simple example: I create a folder on a child domain's DC and want to leave
access to only Enterprise Admins from root domain. I set all the perms, take
ownership to Ent. admins., but child domain's admin still easily can re-take
ownership and change ACL.
Is it possible to solve?
Thanks,
Gera