TwistedHelixis Posted May 19, 2017 Posted May 19, 2017 (edited) Well I obviously do not fully understand permissions. I was told way back that if I create a new domain admin user, to make sure I also add them to local admins group, normally using restricted groups or similar, aparantly so i can use the account to make changes to client computers( if needed), and this is what I have always blindly done. But today I setup a new server, created a seperate domain admin account (right click on administrator and copy) but totally forgot to add my new user to any other groups. I then joined a couple clients to the network, installed software, etc etc, but have only just remembered that I forgot to add the local admins group. Have I always been wrong in this assumption???? Why would I have been told to do it like this, is there a reason? Edited May 19, 2017 by TwistedHelixis
MatthewL Posted May 20, 2017 Posted May 20, 2017 If you are copying a domain admin account, as standard when joined to a domain this group is added to the local admin's of that server/computer. Also not sure if its still default but a user could add up to 10 machines to a domain in the past using a standard domain user account.
ADMaster Posted May 20, 2017 Posted May 20, 2017 Domain admins are a part of local admins by default, second paragraph. https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-f--securing-domain-admins-groups-in-active-directory Domain Admins are, by default, members of the local Administrators groups on all member servers and workstations in their respective domains.
TwistedHelixis Posted May 20, 2017 Author Posted May 20, 2017 So do you think the person who told me to use restricted groups had accidentally done this on the domain admin account at some point, which I assume wipes out all group memberships, and it was simpler for him to leave it like that and let restricted groups wipe and add at each login? These networks have been like this for many many years, so I will add it to my list and take a look during the summer.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now