Home All Groups Group Topic Archive Search About

Limit user Admin access ...

Author
1 Jul 2005 1:47 AM
Mike T.
Hello everyone, I'm just trying to confirm on how to do something.

I'm looking to limit a end user to Domain Admin priv's on a select number of
servers for them to support and nothing else.

I thought there was something I could do through Group Policy - but cannot
find anything.  So my next thought was put them in the Domain Admins group
and give them logon locally access on the specific servers.

Is there any other way to take care of this?

Mike

Author
1 Jul 2005 4:52 AM
John Slattery
Mike, you'd probably do better on a Windows security newsgroup.  This group
is for MS Access security issues.

Show quoteHide quote
"Mike T." <Mi***@discussions.microsoft.com> wrote in message
news:0C70318A-2A51-4E75-841F-0093CC707D22@microsoft.com...
> Hello everyone, I'm just trying to confirm on how to do something.
>
> I'm looking to limit a end user to Domain Admin priv's on a select number
> of
> servers for them to support and nothing else.
>
> I thought there was something I could do through Group Policy - but cannot
> find anything.  So my next thought was put them in the Domain Admins group
> and give them logon locally access on the specific servers.
>
> Is there any other way to take care of this?
>
> Mike
Author
1 Jul 2005 11:10 AM
Mike T.
John,

You are correct - I didn't realize it at first and there's no way to remove
a posting once it's been sent :)

Thank you!

Mike

Show quoteHide quote
"John Slattery" wrote:

> Mike, you'd probably do better on a Windows security newsgroup.  This group
> is for MS Access security issues.
>
> "Mike T." <Mi***@discussions.microsoft.com> wrote in message
> news:0C70318A-2A51-4E75-841F-0093CC707D22@microsoft.com...
> > Hello everyone, I'm just trying to confirm on how to do something.
> >
> > I'm looking to limit a end user to Domain Admin priv's on a select number
> > of
> > servers for them to support and nothing else.
> >
> > I thought there was something I could do through Group Policy - but cannot
> > find anything.  So my next thought was put them in the Domain Admins group
> > and give them logon locally access on the specific servers.
> >
> > Is there any other way to take care of this?
> >
> > Mike
>
>
>