There is a whitepaper from Lucent that describes how to restrict enterprise
admins from domain access at
http://www.lucent.com/livelink/161922_Whitepaper.pdf Is that what you are
tring to do?

-gil

-----Original Message-----
From: Lori Demkovich [mailto:LDemkovich@;infosysinc.com] 
Sent: Tuesday, October 29, 2002 9:50 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] domain admins


I would like to create a group that can fully adminstrate our AD forest but
is NOT a member of domain admins.  How do I get started?
 
I created a group and added the members (groupa).
I then added GroupA to the local administrators group on each server. I also
Delegated GroupA full control of the company.com object in ADU&C.  (Later
we'll delegate by OU)
 
Yet the members cannot do anything.  What am I doing wrong?
 
Lori
.+-wȆi0g-튺+YbʲmPi⁔0敺-튺+b���ڪf.+-j!硶0j!ᤊor眠yثIᚊV+v*
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to