Active Directory Privileges for new admins

Tags:
Active Directory
Administrative privileges
Windows Security
When a new user is added to our Active Directory database, by default, that user has access to all machines. Is there any way to change the domain policy so that, when a user is added, machines are added with this access level by default but, at the same time, deny this option for a second tier admin group? In other words, we have a group with their own admin who is coming into our group, and we would like to make it so this new admin cannot allow their users access to all of our machines.

Answer Wiki

Thanks. We'll let you know when a new response is added.

It sounds like the user is being added to the Domain Administrators group. Simply make sure their account is part of Domain Users and that Domain Users is not in the Local Administrators group on the devices in question. Otherwise, you will need to go through a delegated administrative rights exercise to filter privileges. This is best done using OU and GPO management.

Discuss This Question:  

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following