tangotech Posted February 27, 2023 Posted February 27, 2023 Hi, I'm getting mixed messages online as to what members should be in "Pre-Windows 2000 Compatible Access" Group in AD...
psydii Posted February 27, 2023 Posted February 27, 2023 https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn579255(v=ws.11)#prewindows2000-compatible-access Should be Authenticated Users only, unless your domain dates back to NT4 or earlier and you have some mission critical stuff that was last updated in1996. That said SQL Server and the roots of Cert Services date back this far, so unfortunately: some PKI Admin stuff needs to be members of this group https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn786430(v=ws.11)#delegating-group-permissions as does the the account that runs thr SQL Agent (if you have SQL server in the domain) https://learn.microsoft.com/en-us/sql/ssms/agent/select-an-account-for-the-sql-server-agent-service?view=sql-server-ver16#windows-domain-account-permissions
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now