Permissions for Server Team

Anup Ghonge 21 Reputation points
2020-09-29T06:58:40.743+00:00

Hello All,

We have 4 Domains, out of 4 we have one root domain. The Member servers are managed by a dedicated team, they required admin access on all member servers across all the child domain.
I am looking for some input if there is any better way than we are currently configured. We have created a universal group in root domain
The universal group is being configured in GPO to be pushed in Local Administrator of member servers.

All our DC are on 2016 and Member servers are 2012R2 and 2016..

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,314 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,437 questions
0 comments No comments
{count} votes

Accepted answer
  1. Daisy Zhou 22,476 Reputation points Microsoft Vendor
    2020-09-30T10:04:16.953+00:00

    Hello anonymous user

    Thank you for posting here.

    Basedon the description above, we want to a dedicated team group have local Administrator right on all the member server of all the domains (including root domain and child domains), if I understand it right, I think the way you are configuring is very good. Because it can meet your need and we can set it in batches.

    We can use one of the group policy settings:
    Computer Configuration\Policies\Windows settings\Security Settings\Restricted Group

    Or

    Computer Configuration\Preferences\Control Panel Settings\Local Users and Groups

    Hope the information above is helpful.

    Best Regards,
    Daisy Zhou

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Anup Ghonge 21 Reputation points
    2020-10-01T05:30:39.127+00:00

    Thank you for your reply. But still we need to create a Universal group in root domain to configure in one of the GPO?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.