Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
NTServer Access Level for Domain Administration
Message
General information
Forum:
Windows
Category:
Administration & Security
Miscellaneous
Thread ID:
00455096
Message ID:
00455542
Views:
28
>I have a system admin that has been dumped from Server Administrator rights due to new security restrictions here. The only server access he really needs is to be able to Add/Remove global users to/from local domain groups I have created, using User Manager.
>
>I have tried setting him to a Server Operator, but that doesn't cut it, he's denied access. Is there any other "lesser user rights" option besides Administrator for him to do his task?

I've found a 2-step workaround that will suffice:

1) As Server Operator, one can add/remove user permissions to Shares by logging on the server directly. Thus, the system admin can use this method for quick changes instead of calling me constantly. But in the long run, this is a messy way to do business, having lengthy lists of users set at the Share level, so hence part 2:

2) I will come around to the server periodically to adjust the Local Domain Groups by adding/removing the changes the system admin has made to the Shares, and then cleaning up the Share permissions.

Not perfect, but it'll have to do unless I find something better.
The Anonymous Bureaucrat,
and frankly, quite content not to be
a member of either major US political party.
Previous
Next
Reply
Map
View

Click here to load this message in the networking platform