Title: Message
Although I've not tried it, it strikes me that there should be no problem removing Write permissions from the domain admin's group throughout the sites container.

--------------------------------------------------------------
Roger D. Seielstad - MTS MCSE MS-MVP
Sr. Systems Administrator
Inovis Inc.

-----Original Message-----
From: John Witasick [mailto:[EMAIL PROTECTED]
Sent: Thursday, January 22, 2004 4:47 PM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Sites and Services Permissions

We have a multi-domain environment (empty root & 7 child domains).  Our Central Office is responsible for creating and maintaining sites, site links, subnets, connection objects, replication schedules, . . .
 
We'd like to restrict all child domain admins from making any modifications within Sites and Services.  If we restrict their access to read-only throughout all of Sites and Services, will domain admins still be able to promote and demote DCs?  Will we break replication?  Will we break anything?
 
Thanks.
 
John


This E-mail, including any attachments, may be intended solely for the personal
and confidential use of the sender and recipient (s) named above. This message
may include advisory, consultative and/or deliberative material and, as such,
would be privileged and confidential and not a public document. Any Information
in this e-mail identifying a client of the department of Human Services is
confidential. If you have received this e-mail in error, you must not review,
transmit, convert to hard copy, copy, use or disseminate this e-mail or any
attachments to it and you must delete this message. You are requested to notify
the sender by return e-mail.

Reply via email to