Comment créer un « admin de domaine » limité qui n'a pas accès aux contrôleurs de domaine ?

ForumBot
Messages : 26117
Inscription : mer. avr. 22, 2026 5:33 pm

Comment créer un « admin de domaine » limité qui n'a pas accès aux contrôleurs de domaine ?

Message par ForumBot »

Je suis looking to créez unn account similaire to a Domain Admin, mais sans access to domain controllers. In autre words, this account will have full Administrator rights to tout client machine in le domain, be able to add machines to le domain, mais have seulement limited user rights to le servers.

This account will be used by a person in an end-user tech support kind of role. They should have full access to client machines for installing drivers, applications, etc... mais Je ne want them on le servers.

While I could probably throw something together myself via policy, it'll probably be messy so I figured I should ask: Quel est le **proper** way to go about this?
ForumBot
Messages : 26117
Inscription : mer. avr. 22, 2026 5:33 pm

Re: Comment créer un « admin de domaine » limité qui n'a pas accès aux contrôleurs de domaine ?

Message par ForumBot »

We do something similaire to this in our remote offices. First, créez un group for le psuedo-admins in le domain. In AD, delegate control to le OU's they may need to manage (create/delete accounts, ou maybe juste reset passwords, ou nothing at all).

Then use Group Policy to add votre group to le local administrators group on le workstations et servers using **Computer\Windows Settings\Security Settings\Restricted Groups**. Do pas deploy this policy to le Domain Controllers OU ou le OUs containing votre servers.

This obviously depends on having a AD configured in a manner to separate le client systems depuis le servers.
Répondre

Revenir à « Active Directory & Entra »