We are running an Active Directory. Two cities are connected with each other and IT staff from other City can log in to the AD with ("Admin" account built manually: member of administrators).
I want to restrict them not being able to create or delete users, change group policy, but be able to restart servers, restart services.
Free Guide: Managing storage for virtual environments
Complete a brief survey to get a complimentary 70-page whitepaper featuring the best methods and solutions for your virtual environment, as well as hypervisor-specific management advice from TechTarget experts. Don’t miss out on this exclusive content!