Computing.Net > Forums > Windows 2000 > Local Admin on Domain Controller?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Local Admin on Domain Controller?

Reply to Message Icon

Name: Georgee
Date: May 13, 2003 at 06:34:43 Pacific
OS: Windows 2000
CPU/Ram: P4
Comment:

Any ideea how to make an user LOCAL administrator on a Domain Controller ?
He does not need to have any rights as a domain admin , but to be able to
install , hardware , software on the DC.



Sponsored Link
Ads by Google

Response Number 1
Name: illu510n
Date: May 13, 2003 at 06:37:42 Pacific
Reply:

According the microsoft manual it's impossible to log on locally on a domain controller.


0

Response Number 2
Name: marc2003
Date: May 13, 2003 at 09:47:17 Pacific
Reply:

give them server operator rights.


0

Response Number 3
Name: Glen
Date: May 13, 2003 at 10:13:39 Pacific
Reply:

illu510n, if you are going to quote Microsoft, at least quote them correctly. It is not impossible to log in locally to a domain controller. By default, non-administrators are not given the right to log on locally. Administrators obviously can, and they can also set permissions to let anyone log on locally to the DC.

Server operator may not give all the permissions required.

To answer the question correctly - on a domain controller there are no local accounts. There is no such thing as a LOCAL administrator since there are no local accounts. All accounts are domain accounts. Look in the Computer Management Console on a DC and you'll see the Local Users and Groups is X'ed out reflecting this fact.

Installing applications on a DC has very obvious security considerations. Your best bet would be to enable a temporary account to perform the install if this person is not a domain admin, or use another server. Remember, a DC does not need to be a powerful machine.



0

Response Number 4
Name: christo
Date: May 13, 2003 at 23:18:53 Pacific
Reply:

Once you promote a W2K member server to a DC
you cannot ad local users. The local users and groups option in computer management is crossed out.
the only user / users will be those that where created before promotion to a DC


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 2000 Forum Home


Sponsored links

Ads by Google


Results for: Local Admin on Domain Controller?

Local printing on domain www.computing.net/answers/windows-2000/local-printing-on-domain/41641.html

VPN on domain controller www.computing.net/answers/windows-2000/vpn-on-domain-controller/38386.html

Additional domain controller www.computing.net/answers/windows-2000/additional-domain-controller/63522.html