Announcement

Collapse
No announcement yet.

Universal Groups Confusion | Windows Server

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Universal Groups Confusion | Windows Server

    Got it Sir ,
    Refer to the attached Document.

    The Question is whether Forest Root Admin is having Admin Level Access and Priveleges at
    Child Domain Member Servers / Domain Clients
    Attached Files
    Last edited by harmandeep; 23rd September 2008, 13:45.
    Blog: http://VirtualizationMaximus.com
    OS ... VirTuaLiZaTioN ... MaxiMuS ... Fair, Good, Better, Best



  • #2
    Re: Universal Groups Confusion | Windows Server

    1) ask a normal question please on the forum
    2) attach the imagefile to the topic instead of linking it somewhere else. It really slows everything down in this topic.
    3) read the forum rules: http://forums.petri.com/announcement.php?f=25
    Marcel
    Technical Consultant
    Netherlands
    http://www.phetios.com
    http://blog.nessus.nl

    MCITP(EA, SA), MCSA/E 2003:Security, CCNA, SNAF, DCUCI, CCSA/E/E+ (R60), VCP4/5, NCDA, NCIE - SAN, NCIE - BR, EMCPE
    "No matter how secure, there is always the human factor."

    "Enjoy life today, tomorrow may never come."
    "If you're going through hell, keep going. ~Winston Churchill"

    Comment


    • #3
      Re: Universal Groups Confusion | Windows Server

      Please put your question in the text, not as part of the image
      My connection is too slow to download it all in a reasonable time!
      Tom Jones
      MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
      PhD, MSc, FIAP, MIITT
      IT Trainer / Consultant
      Ossian Ltd
      Scotland

      ** Remember to give credit where credit is due and leave reputation points where appropriate **

      Comment


      • #4
        Re: Universal Groups Confusion | Windows Server

        I thought Ent Admins only got admin rights to DC's within child domains not member servers/computers is that right or do I have it skewed?
        cheers
        Andy

        Please read this before you post:


        Quis custodiet ipsos custodes?

        Comment


        • #5
          Re: Universal Groups Confusion | Windows Server

          Originally posted by AndyJG247 View Post
          I thought Ent Admins only got admin rights to DC's within child domains not member servers/computers is that right or do I have it skewed?
          Enteprise Admins is a Universal group that is located in the Forest Root Domain, and only there. Since it's a Universal group, it cannot be placed into Global groups in any domain in the forest, only into Domain Local groups.

          On a DC, Administrators is a Domain Local group.

          DCs replicate their database, therefore, make someone a member of the Administrators group on one DC in the domain, and in fact you give him or her power on all DCs in the domain.

          Because of that, members of the Administrators group on a DC only have power over Domain Controllers, and NOT over any member server or workstation.
          Cheers,

          Daniel Petri
          Microsoft Most Valuable Professional - Active Directory Directory Services
          MCSA/E, MCTS, MCITP, MCT

          Comment


          • #6
            Re: Universal Groups Confusion | Windows Server

            the main reason why Ent Admins are needed is for changes to the forest structure that effect the entire forest and not only the domain.
            and less for handling specific Tasks in the domains.
            e.g in multiple domains any changes to the configuration partition (e.g. Sites/Sitelinks/etc) require Ent Admins.
            Last edited by Akila; 25th September 2008, 09:55.

            Comment

            Working...
            X