How can configure "Account Operator Rights" to cannot User Account in Domain Admin Group ?

Navy Chan 1 Reputation point
2020-08-03T06:33:35.5+00:00

How can configure "Account Operator Rights" to cannot User Account in Domain Admin Group ?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,449 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Vicky Wang 2,731 Reputation points
    2020-08-04T08:43:47.6+00:00

    Hello,

    this is the official description form Microsoft about the Account operators:

    "Members of this group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain, except the Domain Controllers organizational unit. Members of this group do not have permission to modify the Administrators or the Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. Members of this group can log on locally to domain controllers in the domain and shut them down. Because this group has significant power in the domain, add users with caution."

    Personal i would not use the account operators group as they have lot's of permissions. I prefer to use an own created security group and then use "Delegate control" wizard on the OU where they should have the permission to work. See this great article from Jorge about delegating several admin tasks:

    http://blogs.dirteam.com/blogs/jorge/archive/2006/01/05/369.aspx

    Another important part of the account operators is, that this group is a protected group where AdminSDHolder comes into play, each hour the security settings will be reset automatically:

    http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx

    0 comments No comments

  2. Vicky Wang 2,731 Reputation points
    2020-08-12T06:13:52.673+00:00

    Hi,
     
    Just want to confirm the current situations.
     
    Please feel free to let us know if you need further assistance.
     
    Best Regards,
    Vicky 

    0 comments No comments

  3. Vicky Wang 2,731 Reputation points
    2020-08-17T07:06:44.637+00:00

    Hi,
     
    Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
     
    Best Regards,
    Vicky

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.