IF i provide to one user to change group membership delegate on Domain then that id would be able to change enterprise admin domain admin members and make its id in enterprise admin group?


if provide 1 user change group membership delegate on domain id able change enterprise admin domain admin members , make id in enterprise admin group?

if asking, if granted ability modify enterprise admins group able add themselves?  answer yes , no.  believe can temp change group system reset permissions on group via adminsdholder.  security control mechanism within ad.

http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx

--
paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security+, bs csci
2008, vista, 2003, 2000 (early achiever), nt4
http://www.pbbergs.com    twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson

please no e-mails, questions should posted in newsgroup. posting provided "as is" no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607