There is a whitepaper from Lucent that describes how to restrict enterprise admins from domain access at http://www.lucent.com/livelink/161922_Whitepaper.pdf Is that what you are tring to do?
-gil -----Original Message----- From: Lori Demkovich [mailto:LDemkovich@;infosysinc.com] Sent: Tuesday, October 29, 2002 9:50 AM To: [EMAIL PROTECTED] Subject: [ActiveDir] domain admins I would like to create a group that can fully adminstrate our AD forest but is NOT a member of domain admins. How do I get started? I created a group and added the members (groupa). I then added GroupA to the local administrators group on each server. I also Delegated GroupA full control of the company.com object in ADU&C. (Later we'll delegate by OU) Yet the members cannot do anything. What am I doing wrong? Lori .+-wȆi0g-튺+YbʲmPi⁔0敺-튺+b���ڪf.+-j!硶0j!ᤊor眠yثIᚊV+v* List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
