Logging onto Domain Controllers as a Non Domain Admin


is possible give a user access log domain controller , administer file share on dc without making them member of domain admins?

i know not security best practise have dc act file server budget contstraints have not allowe me seperate dc , file share functions onto 2 seperate servers.

now i'd give admin rights log onto dc not make changes dc or , ad components (sites & services, dns etc.).

has come across type of requirement before?

i've tinkered around default domain controllers policy , giving user account rights log dc using ts has not worked.

thanks in advance replies.


pajoryan123

hi,

allowing user logon first step. administer shared folder, should give user ntfs permission of shared folder. add user in security tab, give full control permission or other permissions.

to change ad settings, open aduc, right-click ad object, choose properties, switch security tab, can configure permission configuring ntfs.

thanks.


this posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file