
close
close
It’s common that IT staff are given domain administrator rights for a number of reasons, one being that it’s a convenient way to log on to workstations with local administrator privileges. But from a security standpoint, giving high-level access to Active Directory (AD) for the sake of an easy life, puts your IT infrastructure at risk.
First we need to create a management group in Active Directory for users who will have rights to log on to workstations with administrative privileges.
advertisment
Now I’m going to create a GPO to add the new AD group to the local Administrators group on all my workstations. I recommend that you create a separate Organizational Unit (OU) for your workstation computer accounts. While it’s possible to apply Group Policy to computer objects in the default Computers container, it would mean linking the GPO to the domain and filtering out domain controllers and member servers.
The next time Group Policy applies to computers in the workstations OU, the AD\Workstation Administrators group will be added to the local Administrators group, enabling IT administrators to manage workstations without domain admin privileges.
More in Active Directory
How to Fix the "An Active Directory Domain Controller for the Domain Could Not Be Contacted" Error
Jun 20, 2022 | Michael Reinders
Learn How Organizations Are Using Semperis Purple Knight to Secure Active Directory
Jun 7, 2022 | Russell Smith
Microsoft Releases Out-Of-Band Patches to Fix Windows AD Authentication Issues
May 20, 2022 | Rabia Noureen
Cloud Conversations – Ståle Hansen on Digital Wellbeing and Viva Explorers
May 19, 2022 | Laurent Giret
Most popular on petri