How to Restrict a member of Administrators?

25 pts.
Tags:
Active Directory
Local Administrators Group
User Permissions
We are running an Active Directory. Two cities are connected with each other and IT staff from other City can log in to the AD with ("Admin" account built manually: member of administrators). I want to restrict them not being able to create or delete users, change group policy, but be able to restart servers, restart services.

Answer Wiki

Thanks. We'll let you know when a new response is added.

Use a security group that gives them administrative rights on all servers and workstations so they can maintain/service machines. Add the group to the builtin server operators group. They are not domain admins or account operators so they cannot create users or work with GPOs.

Discuss This Question:  

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following