limited admin rights

  • Thread starter Thread starter Paul Edwards
  • Start date Start date
P

Paul Edwards

Is there a way in a windows 2000 Active directory domain to give someone
admin rights over a specific group of computers and not have access directly
to the AD server.

Example...
Give someone in a business department an account with rights to install
programs on computers ONLY in the business department. This user also would
not beable to login to any of the AD domain servers.

I would like to stay away from "Local Accounts"

Thanks

Paul
 
Hello,

You could delegate control to an OU. See:

http://www.microsoft.com/windows2000/techinfo/reskit/en-us/default.asp?url=/
windows2000/techinfo/reskit/en-us/cnet/cncf_imp_xpqf.asp

Dale Weiss MCSA MCSE CISSP
PSS Security

This posting is provided "AS IS" with no warranties, and confers no rights.
Any opinions or policies stated within are my own and do not necessarily
constitute those of my employer. Use of included script samples are subject
to the terms
specified at http://www.microsoft.com/info/cpyright.htm
 
Back
Top