Structuring accounts for logging into servers (advice)
hi all,
i have domain computers , users (standard setup). wondering, how structure accounts logging servers?
for example, create group in ad users , call group "local admins", , add group servers via gp.
or use managed attribute on ad?
what's best approach?
hi,
based on research, “manage by” tab informational, still need delegate control user/group has appropriate access permissions on object.
here is related link below suggest refer to:
"managed by"
best regards,
amy wang
Windows Server > Directory Services
Comments
Post a Comment