Creating limited admin account

Hello,
We are using Win2008R2 Std Active Directory and I would like to create a new group for new IT starters. They will need access to join computers to the domain, install software on domain computers, look at logs, run maintenance tasks and create accounts and
reset passwords. I don't want them to be able to mess with domain admin accounts.
I have created a group "First Line" and made it a member of "Account Operators", "Performance Log Users", "Performance Monitor Users" and "Print Operators". I assigned my test user to the group and logged
onto a domain computer using the account. I found that I could reset the domain Administrator's password!
Please could someone explain what I'm obviously misunderstanding here? How can a non-admin change admin passwords? Am I going about this all wrong?
Thanks in advance.
Elliot

Hi Elliot,
Based on my research, under normal circumstances, members reside in Account Operators group should not be able to modify Domain Administrators, nor the Domain Controllers OU, which is by design.
Moreover, the Account Operators group belongs to Protected Groups, which means that the ACL of this group is fixed because a background process runs every hour by default to make sure that the ACL stays the same.
Have you added this user to the domain admins group accidentally?
More information for you:
Default groups
http://technet.microsoft.com/en-us/library/cc756898(v=WS.10).aspx
can account operators reset domain administrator password?
 http://social.technet.microsoft.com/Forums/windowsserver/en-US/bcda44e8-0056-4b53-9c66-ffeebe85e86e/can-account-operators-reset-domain-administrator-password?forum=winserverDS
AdminSDHolder, Protected Groups and SDPROP
http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx
Best Regards,
Amy Wang

Similar Messages

  • How Do I create an Admin account?

    Hi
    This sounds silly but.... How do I set up an administrator account ?
    I am using DW CS3 and ADDT and PHPMYADMIN
    I can create a table with a level_user field and al the other usual fields
    I can use the login wizard and / or the ADDT control panel to set and add user levels so I have added user and admin levels and I can figure out the rest I think but h I have read many tutorials and I still can't figure out how to create an admin account? I have thought I have to create a temp form with a level field just to upload my admin level into the user_level field in my database table, say level "1" and then creat another form with no user level field for users to upload their info and have their level set by the default value in the login wizard say level "2"
    Does this sound like the correct way to go about thing?
    Is there a better more logical way to do this?
    I have asked this question in the nonrmal dreamweaver and I was told to
    "Use a frontend like PHPMyAdmin to construct the db and set one of the account's user levels to something like "admin" instead of "y" or whatever and then filter on "admin."
    I really don't understand this as I only want to set acces levels to one table so that I can delete records as administrator and so that noone else can access certain pages
    Anyone got any ideas?
    Any help would be more than helpful
    Have a nice day

    Hi Charis,
    I have asked this question in the nonrmal dreamweaver and I was told to
    "Use a frontend like PHPMyAdmin to construct the db and set one of the account's user levels to something like "admin" instead of "y" or whatever and then filter on "admin."
    folks in the regular DW forums don´t necessarily know how ADDT handles the "user levels", so here´s my suggestion:
    a) create the ADDT "login" table with PhpMyAdmin, add one default record
    (probably your own account) and set its "level_usr" column´s value to "1"
    b) add this very column to ADDT´s array of session variables within the Control Panel and name it, say "kt_level"
    I really don't understand this as I only want to set acces levels to one table so that I can delete records as administrator and so that noone else can access certain pages
    once you have the additional session variable "kt_level" defined, you can always filter against this one -- for example...
    a) in a "Show If Conditional Region"
    (for hiding certain page elements)
    b) in a "Restrict Access To Page" behaviour
    (to prevent access to a whole page)
    and then creat another form with no user level field for users to upload their info and have their level set by the default value in the login wizard say level "2"
    that´s a good approach :-)
    Cheers,
    Günter Schenk
    Adobe Community Expert, Dreamweaver

  • Creating new admin account and deleting old one

    I am handing my MacbBook Pro to my wife
    I am thinking about deleting my account (which is an admin, of course). I made her an admin account and she has access to all my apps when she logs in...
    I WANT her to have access to my applications as if they were hers even when my account is deleted (e.g. Adobe CS3, Skype, etc.).
    My Question:
    When I delete my admin account (with which the applications were installed), will she automatically not have access to the apps in the "applications folder" anymore? In other words, when I delete the admin account with which the application where installed, do all applications and setting from that account get deleted as well from all other users?
    Thank you.
    (transfering, sync'ing, etc. can be so easy but such a headache from a personal standpoint: managing changes)

    So, this would create her a new admin account but:
    1. my old account folder will be there but without being associated with a user
    2. same for her old folder
    3. all I have to do is drag her old account's application folder + application support folder onto her new admin account and all applications would run like we never even even left her old account behind?
    Will any Leopard boot CD work or does it have to be one made specifically with her computer (it didn't come with a boot CD)...
    thanks...

  • Migration problem (created second admin account)

    So I just got a new Macbook Pro and wanted to transfer my music and documents from my time machine from my old Macbook.
    I did it, but now I have a second Admin account with the music and documents. I don't want a second admin account and would like to delete it.
    I only want one admin account, so how would I migrate the music and documents from the time machine to my current admin account?
    So my questions are how do I delete the second admin account that was created and just mirgate it to the current admin account?
    Another question that is off topic is: the feature on safari that when you quit safari that it opens up the same window. Can that be changed to just being the homepage at all times when I reopen safari after it was quit?

    Drag them over to the original accounts Public folder, or move them to the hard drive level Users/Shared folder. You may experience some permissions problems you will have to fix.

  • Trying to create a admin account to do a erase and reinstall of Mac OS X

    I just purchased a iMac G4 on eBay and I can't reformat the drive without his user password, is there a way to bypass that so I can reinstall Mac OS X. I tried making another account but the prefs are locked.

    You can try holding down command-O-F when you boot. Once it's booted, type (without the quotes) "reset-nvram" then hit return
    then type "reset-all" then hit return
    The Mac should then reboot. Try formatting the HD again.

  • Limited Admin Privileges/Specific Elevation of User Accounts

    I'm hoping to create an account on my laptop for my roommate.  I don't want him to have a full admin account, but he knows enough about computers that he could troubleshoot networking, and I want to enable him to install programs on the system.  I'm not sure what the best way to go about creating an account which can elevate itself for specific tasks; I've never modified my sudoers file before, and I don't know how to do so to grant him access to the privileges he should have.  I don't want to force him to use Terminal; I'd rather have him be able to enter a username/password for Admin privileges when prompted, whether that's his standard user account or a limited Admin account, but I want to make sure that account DOESN'T have access to modify anything in Users & Groups, can't create accounts with dscl, can't modify the keychain or hard drive partitions, etc. 
    Am I right in thinking the sudoers file is the best way to approach this?  How do I find out what processes to allow access to?  Does Network Preferences, for example, have any dependencies he will also need to be able to run?  Also, is there a good starting point/article on modifying the sudoers file for this type of thing anywhere?  <<clearly googling the wrong thing because my searches just tell me how to add someone to the sudoers file>>

    To modify network settings he needs to be able to unlock the preference pane. If you can unlock one pane you can unlock them all including Users & Groups.
    While it is more feasible allow him some latitude in the application installing scenario it's going to be a pain. The non-server version of OS X is just not setup for this. Either a user has admin privileges or he doesn't there is no part way.
    Again if you trust him then you should also trust him not to do what you don't want him to do. If you tell him he can do x but please don't do y and you think he won't abide by your rules then giving him any access is potential trouble.
    And again if he can get to the machine when you are not around he can do what he likes, privileges or no privileges.
    good luck,
    regards

  • Multiple admin accounts, need to delete one of them ... what happens?

    Ok, short story shorter - broke up with my GF and she has an account on my laptop.
    She has saved all her stuff, so I'm not worried about loosing personal files/documents.
    My question is though, what else may be lost that I should be careful of.
    • Will programs be lost?
    I installed Adobe Suite through her account, will that be removed as well? That's an application though, that I set for 'all users'.
    • Will there be any change to system, or cause errors if that was the main Admin account?
    By deleting an Admin that was in use 50% of the time, are there any system problems that may happen after I delete?
    From what I remember, the system when I created another Admin account it just treated it as if someone just set up their MBP for the first time - ie. they seem to be completely independant.
    Basically, I just want to make sure my experience (in my account) does not change once I've pressed the delete button.
    Much thanks in advance.
    -NTFW

    Thanks andyBall_uk,
    I can confirm that there are no files/data/passwords that I'm concerned about loosing on the account I want to delete.
    *BUT, on the account I want to delete - I installed Adobe Illustrator/Photoshop.
    These programs are usable on my account as well, I see them in my Application folder even though I only installed it once.
    Are you saying it will delete Adobe Illustrator/Photoshop because it was installed on that Admin account?
    Thanks very much for the help!

  • Is there a way to create a user account that "expires", or self deletes itself after a set amount of time?

    I am hoping to find a way to create an Admin account for our parent body that can be used for items at home, "adding printers, software, wireless settings, etc...), but have that account either "expire" or self delete itself after say 72 hours?
    Thoughts?
    Jesse

    Will they be needing to keep files saved for a while?  I'm guessing no, since you're ok with it auto-deleting after a short while.
    You could just use the guest user:  http://support.apple.com/kb/PH11321
    But I'm not aware of any way that you could setup an account to expire.

  • Can't Login to Local Admin Account

    Over the weekend I rebuilt an OS X 10.4.10 Server.
    I created a local admin account, then set up DNS & OpenDirectory Master. I created some admin accounts in the domain.
    I also set up a Panther Server as "Connected to a Directory System" and joined it to the Kerberos server on the 10.4 server.
    All the clients are connecting to the domain, and everything is working except I can't log in to the 10.4 server with the local directory accounts anymore. I have created a new account in the local directory and tried changing the passwords, but nothing works for logging into the local directory admin accounts. With the exception that I am able to SSh into the local directory accounts.
    Any suggestions?
    Message was edited by: iGary

    Does this help?
    http://docs.info.apple.com/article.html?artnum=307005
    LN

  • Multiple Contribute Admin Accounts

    Hey,
    I am trying to use Contribute to edit a Template file made in
    Dreamweaver for an HTML email. I know its not the best way of doing
    things, but all the office need to do is change the text, so its
    working just fine except for CSS. I have found that some email
    clients (like gmail or yahoo) do not support CSS formated text in
    the email. I have also found that the only way to change what
    Contribute uses (CSS or not) is with an Admin account. I have an
    Admin account for the main site, but I do not want to disable CSS
    for the main site. I only want to disable CSS for a sub folder
    where I will store the HTML files. Right now I have a sub folder,
    linked to an FTP user name and only allows them to upload to that
    sub folder. That's where I am now.
    So, all I need to know is how to create an Admin account for
    only a sub folder. That way, I can use Contribute go into the Admin
    Panel and disable CSS, but only for the sub folder. Thanks for any
    help!

    In the Standalone version BIP uses the same credentials to connect to the datasources, irrespective of the user logged in, hence I cannot think of how this restriction can be done, perhaps in a future release this may be supported.
    In the BI publisher that comes embedded with systems, like JDEdwards, Siebel, etc The security is controlled by the user rights assigned to the user in the application BI Publisher is embedded with.
    If your requirement is Binding, you may want to consider a different Instance of BIP for each exclusive datasource.

  • Hidden admin account not working after updating to ML

    on Lion, i created a hidden admin account called ".admin" [the dot making it hidden]. this was my only admin account. after upgrading to Mountain Lion, the password is not accepted. it typically didn't show up in the user list and i can't access it from login screen. i do see a "admin" [no dot] folder in the Users folder. but any attempts at logging in to that failed also.
    i don't have any other admin accounts, so i'm not sure how to create an admin account from a standard user account.

    If you need that admin account and its home directory back, I think you will have to restore from your backup, unhide the admin's home directory and then re-do the upgrade.
    I think what happened is that the hidden admin's also hidden home directory was either ignored or overwritten during the update.  You'd have been better off assigning it a UID below 500, hiding the UID<500 group, and moving that admin's home directory to somewhere else (/var or /opt maybe), but not making the actual home directory hidden.
    some useful info (for the future) is here - http://support.apple.com/kb/HT5017?viewlocale=en_US

  • 2nd attempt--Cannot Install E-Learning Suite 6.1--Even as New Admin Account

    PLEASE HELP ME FURTHER WITH THIS UNRESOLVED TECH TICKET ISSUE
    CANNOT INSTALL ADOBE ELEARNING SUITE 6.1
    Adobe เคสอัพเดท : 0185404686 : Mohammed U
    บัญชี Adobe ของคุณคือ [email protected]
    หมายเลขเคสของคุณคือ0185404686
    การบรรยายลักษณะเคส:Chat:Installation Help (CH13860513)
    You contacted us as you were unable to install e-learning suite. We suggest you to create a new Admin account on your computer and try installing creative cloud desktop from there. Once you are able to install and launch on new admin account you will be able to access it from your normal admin account as well. Refer this link to create new admin account
    http://support.apple.com/kb/PH4600
    Hello,
    Thank you for your reply. However, YOUR solution did not work.
    I created a completely new admin account. Everything was fresh -- totally virgin. And, exactly the same occurred. The installer program completed about 50% of its run,and then froze up. It failed to initialize, and I was referred to an onsite help page that has been discontinued ... that is no longer supported.
    What can I do?
    I have purchased AN EXTREMELY EXPENSIVE DVD from Adobe, had it sent to me in Thailand, and it will not install in my computer.
    Please provide me with the technical support that I need.
    Thank you.
    Neal Davis

    Hi There,
    Can you confirm your operating system on which you are trying to install e LearningSuite 6.1?
    Also confirm the PowerPoint version present on that machine?
    Regards,
    Ajit

  • Migration assistant won't migrate admin account

    On my G5 I created the admin account (which is the account I usually use) with the same name, short name and password as the admin account on my older machine.
    When I use migration assiatant, it brings up a "Duplicate Account Found" dialogue box which offers to rename the account I am transferring (which I don't want to do as the name is correct on both machines) and do not transfer the user account (which I certainly don't want as transferring the admin account is the whole point).
    The option to replace the existing account with the one I am transfering (which might be the one I want) is greyed out.
    What am I supposed to do? Don't Apple test the most obvious situation?
    Beige G3   Mac OS X (10.3.5)  

    I found that I needed to create another temporary admin account and run the migration assistant from that account. Then the option to replace the original admin account was no longer greyed out.
    I suppose one could enable root and log in as root as well to do this.

  • HELP!  NO ADMIN ACCOUNT

    I have a computer in my department that does not have a admin account. Two user accounts are both standard. I'm stuck - can't install downloads etc. How can I create an admin account?

    Use the instructions in this FAQ to make one of your standard accounts into an admin account.
    (10674)

  • Delete new admin account

    Good day everyone,
    I just upgraded to new OS X. It created another admin account. I already have the previous one. I just want to delete the new admin account. Can someone help me how to do it. I'm new to mac. So, some detailed steps will help.
    Thanks

    Log into the desired account, open the Users & Groups pane of System Preferences, unlock it, and delete the other.
    (91477)

Maybe you are looking for

  • Preview crashing on yosemite whenever i open a pdf file

    preview crashing on yosemite whenever i open a pdf file Hi, Ever since i updated to yosemite my preview app keeps crashing every time I open a PDF file. Can anyone figure this out ? Here is the crash report: Process:           Preview [10399] Path:  

  • How Do I Find How Much "space" My Documents uses

    Were can i find how much hard drive space my documents occupies.  I'm trying to save to the cloud but I'm not sure how much I need to purchase....

  • Import Cost Sheet

    Hi Experts, When we import some material from any country, we pay material cost to the import vendor and other expeses like clearing charges, freight, insurance, custom duty etc to different - different local vendors, Now we want to get a cost sheet

  • Code Groups and Codes for Catalogs

    Hi CRM gurus, how is it possible to replicate in SAP CRM 2007 Codes for Catalogs* from external systems? Does an standard object for replication exist? Thanks in advance, Andrea Ricci *I should replicate codes to be used both in multilevel categoriza

  • Design Notes not showing up in Remote Server column

    I cant seem to see the Design Note icon appear in the appropriate column of the remote server for collaborative use. I think I have set the feature up correctly, and I have uploaded the document in question to the server, but no sign of the notes ico