Avoiding Legacy Built-in Groups

  • Section(s): Active Directory
  • Created on Apr 05, 2006.
  • Last Modified on May 10, 2006.
  • Last Modified by Mitch Tulloch.
  • Rated 4.7 out of 5 based on 3 votes.
How you can avoid using legacy built-in groups to grant admin-level privileges.

Microsoft documentation on this isn't clear, but built-in local groups like Account Operators, Server Operators, and others found in the Builtin container of Active Directory are legacy groups that are basically only there to maintain backward compatibility with Windows NT.

If you want to grant users rights to perform certain tasks like create new accounts, reset passwords, and so on, avoid using these built-in groups and use Active Directory delegation instead. Delegation gives you greater control over which groups of users you can assign to perform different kinds of admin-level tasks, and it's easy to use as well, just right-click on an OU and select Delegate Control and a wizard opens to walk you through the process.

Cheers,
Mitch Tulloch
MVP Windows Server
http://www.mtit.com

 

Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Readers' Choice

Which is your preferred Anti Virus Appliance solution?