|
Actually, I meant to direct this answer at Juan, since it’s his project. Thanks…
<mc> From: Creamer, Mark
Robert, I bet I know where you’re going with this, as we are doing the same type of thing as part of an overall Sarbannes-Oxley compliance project. Basically, we didn’t try to remove Domain Admins’ ability to create users, we simply don’t have any domain admins anymore (at least in the traditional sense). Everything is role based. On the occasion when we need a DA role, the security team moves the person into the role for the duration of the change, and then takes them back out again.
<mc> From: Rutherford,
Robert [mailto:[EMAIL PROTECTED]
This would not make any sense at all as a domain admin is the top admin and could typically get around most security. It may be possible to frig something but you shouldn't even be thinking about it anyway.
What are your reasons for not allowing the domain admin rights to create accounts? It is of course possible to allow another party to create accounts and this is done through delegation.
What is your admin setup and what are you trying achieve?
|
Title: Message
- [ActiveDir] Is it possible ? deny do... "Sanz de Le�n, Juan Carlos"
- RE: [ActiveDir] Is it possible ... joe
- RE: [ActiveDir] Is it possible ... Rutherford, Robert
- RE: [ActiveDir] Is it possible ... Creamer, Mark
- Creamer, Mark
