Permissions to Perform Update

  • Thread starter Thread starter Dave Clark
  • Start date Start date
D

Dave Clark

We are in the planning stages of moving to AD, and am
looking for some ideas/input on the following:

We will be a single domain, with about 17 sites. The
only Domain Admins will be in a single location, each
SITE will have at least 1 DC in the location. The 17
sites will NOT have anyone in the Domain Admins group,
but will be in Server Operators, BU Operators, etc for
some administration. However, I beleive you MUST have
ADMINISTRATOR rights to the local DC to do a Windows
Update.

What would be the best way to allow the local folks do
updates WITHOUT having to be in the Domain Admins group?
 
It that good to consider making use of Software Update Service to do a
centralized update push and approval? After configuring individual server
to retrive update from internal SUS server, this will eliminate the need to
manually trigger patch installation which can in turn eliminate the need of
esculated permission.

Lawrence
 
That is a great idea. I was just thinking about that as
an option this weekend. May have to go that route if no
other way is possible.

Would like to try to see if there is a way to provide
access without giving Domain Admin rights though. But, I
too have yet to figure out a way around it.
 
Dang...I guess no one else has this issue....
-----Original Message-----
That is a great idea. I was just thinking about that as
an option this weekend. May have to go that route if no
other way is possible.

Would like to try to see if there is a way to provide
access without giving Domain Admin rights though. But, I
too have yet to figure out a way around it.
configuring
individual server
.
 
Back
Top