IF i provide to one user to change group membership delegate on Domain then that id would be able to change enterprise admin domain admin members and make its id in enterprise admin group?
if asking, if granted ability modify enterprise admins group able add themselves? answer yes , no. believe can temp change group system reset permissions on group via adminsdholder. security control mechanism within ad.
http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx
--
paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security+, bs csci
2008, vista, 2003, 2000 (early achiever), nt4
http://www.pbbergs.com twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson
please no e-mails, questions should posted in newsgroup. posting provided "as is" no warranties, , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment