Domain Controller Local Users And Groups
It was one of those things that i remember learning but never really thought about until.
Domain controller local users and groups. Does this account for what you experience. What happens to the local users and groups when promoting a domain member to a domain controller. Is it a domain controller. Richard mueller mvp directory services tuesday march 26 2013 2 45 pm text html 3 26 2013 3 33 43 pm arnavsharma 0 0.
Hi all i m trying to change the local administrator on one of my 2008 r2 server. The in short the local users become domain users. Why don t local groups and users exist on a domain controller. Ms have taken great pains to remove local users and groups from the gui tools and even if you tickle up lusrmgr msc directly it complains that the snap in won t run on a domain controller.
Local administrator may not be a good group to add users to on a domain controller however for other purposes like event log reader and the like this worked well. Depending on what your needs are you might be able to add the user or service account into the domain administrators group within active directory. I have a windows server 2008 that i have made to a domain controller by installing ad ds but it was not really what i wanted to achieve with the server so i. You can run command net localgroup to display all groups and chose the one that s best suited for a service account s least privilege access.
Unfortunately domain controllers don t have the local users and groups databases once they re promoted to a domain controller. You cannot use local users and groups to view local user and group accounts once a member server has been promoted to a domain controller. If you want to be more granular with the policy you can set it so it applies only on specific operating systems or to computers that have a specific mac address. However you can use local users and groups on a domain controller to target remote computers that are not domain controllers on the network.
Hi all i am trying to configure windows server 2012 r2. If so yes lu g will be removed because the domain becomes local at that point. The domain users and or groups should be member s of this local group. This is just sort of me wondering out loud.