Logging onto Domain Controllers as a Non Domain Admin
is possible give a user access log domain controller , administer file share on dc without making them member of domain admins?
i know not security best practise have dc act file server budget contstraints have not allowe me seperate dc , file share functions onto 2 seperate servers.
now i'd give admin rights log onto dc not make changes dc or , ad components (sites & services, dns etc.).
has come across type of requirement before?
i've tinkered around default domain controllers policy , giving user account rights log dc using ts has not worked.
thanks in advance replies.
pajoryan123
hi,
allowing user logon first step. administer shared folder, should give user ntfs permission of shared folder. add user in security tab, give full control permission or other permissions.
to change ad settings, open aduc, right-click ad object, choose properties, switch security tab, can configure permission configuring ntfs.
thanks.
this posting provided "as is" no warranties, , confers no rights.
Windows Server > Security
Comments
Post a Comment