Principale utente con più risposte
Legame Domain Admins con Administrators locali

Domanda
-
Buonasera,
Vorrei sapere se il gruppo Domain Admins si associa automaticamente al gruppo locale Administrators, oppure se questa associazione va fatta nella Domain Policy.
C'è un utente ancora più "potente" dei Domain Admins?
Una GPO sul pc con quale utenza viene eseguita?
Grazie.
Risposte
-
Gli utenti membri del gruppo Domain Admins fanno automaticamente parte dei gruppi Administrators locali di tutti i client e i server del dominio. Non serve eseguire alcuna associazione.
By default, the Domain Admins group is a member of the Administrators group on all computers that have joined a domain, including the domain controllers. The Domain Admins group is the default owner of any object that is created in Active Directory for the domain by any member of the group. If members of the group create other objects, such as files, the default owner is the Administrators group.
https://technet.microsoft.com/en-us/library/dn579255(v=ws.11).aspx#BKMK_DomainAdmins- Modificato Fabrizio GiammariniMVP, Moderator martedì 17 gennaio 2017 17:09
- Proposto come risposta Edoardo BenussiMVP, Moderator mercoledì 18 gennaio 2017 08:59
- Contrassegnato come risposta Nicola Venosta mercoledì 18 gennaio 2017 09:31
-
a parte la prima domanda alla quale ha già risposto correttamente Fabrizio, le risposte alle altre due domande sono:
2) non possiamo definire utente più "potente" ma utente che ha permessi maggiori di un utente membro del gruppo Domain Admins è l'utente che sia anche membro del gruppo Enterprise Admins, del gruppo Schema Admins, ecc.ecc. secondo lo schema riportato di seguito
Group or Account Name
Default Location
Description
Enterprise Admins
Users container
This group is automatically added to the Administrators group in every domain in the forest, providing complete access to the configuration of all domain controllers.
Schema Admins
Users container
This group has full administrative access to the Active Directory schema.
Administrators
Builtin container
This group has complete control over all domain controllers and all directory content stored in the domain, and it can change the membership of all administrative groups in the domain. It is the most powerful service administrative group.
Domain Admins
Users container
This group is automatically added to the corresponding Administrators group in every domain in the forest. It has complete control over all domain controllers and all directory content stored in the domain and it can modify the membership of all administrative accounts in the domain.
Server Operators
Builtin container
By default, this built-in group has no members. It can perform maintenance tasks, such as backup and restore, on domain controllers.
Account Operators
Builtin container
By default, this built-in group has no members. It can create and manage users and groups in the domain, but it cannot manage service administrator accounts. As a best practice, do not add members to this group, and do not use it for any delegated administration.
Backup Operators
Builtin container
By default, this built-in group has no members. It can perform backup and restore operations on domain controllers.
DS Restore Mode Administrator
Not stored in Active Directory
This special account is created during the Active Directory installation process, and it is not the same as the Administrator account in the Active Directory database. This account is only used to start the domain controller in Directory Services Restore Mode. In Directory Services Restore Mode, this account has full access to the system and all files on the domain controller.
ref: https://technet.microsoft.com/en-us/library/cc700835.aspx
3) l'appplicazione delle group policies sulle macchine di dominio viene eseguita
a) con le credenziali di localsystem quando si applicano le computer policies ossia allo startup e allo shutdown
b) con le credenziali dell'utente loggato quando si applicano le user policies ossia al login e al logout
ciao.
Edoardo Benussi
Microsoft MVP - Cloud and Datacenter Management
edo[at]mvps[dot]org- Proposto come risposta Edoardo BenussiMVP, Moderator mercoledì 18 gennaio 2017 08:59
- Contrassegnato come risposta Nicola Venosta mercoledì 18 gennaio 2017 09:31
Tutte le risposte
-
Gli utenti membri del gruppo Domain Admins fanno automaticamente parte dei gruppi Administrators locali di tutti i client e i server del dominio. Non serve eseguire alcuna associazione.
By default, the Domain Admins group is a member of the Administrators group on all computers that have joined a domain, including the domain controllers. The Domain Admins group is the default owner of any object that is created in Active Directory for the domain by any member of the group. If members of the group create other objects, such as files, the default owner is the Administrators group.
https://technet.microsoft.com/en-us/library/dn579255(v=ws.11).aspx#BKMK_DomainAdmins- Modificato Fabrizio GiammariniMVP, Moderator martedì 17 gennaio 2017 17:09
- Proposto come risposta Edoardo BenussiMVP, Moderator mercoledì 18 gennaio 2017 08:59
- Contrassegnato come risposta Nicola Venosta mercoledì 18 gennaio 2017 09:31
-
a parte la prima domanda alla quale ha già risposto correttamente Fabrizio, le risposte alle altre due domande sono:
2) non possiamo definire utente più "potente" ma utente che ha permessi maggiori di un utente membro del gruppo Domain Admins è l'utente che sia anche membro del gruppo Enterprise Admins, del gruppo Schema Admins, ecc.ecc. secondo lo schema riportato di seguito
Group or Account Name
Default Location
Description
Enterprise Admins
Users container
This group is automatically added to the Administrators group in every domain in the forest, providing complete access to the configuration of all domain controllers.
Schema Admins
Users container
This group has full administrative access to the Active Directory schema.
Administrators
Builtin container
This group has complete control over all domain controllers and all directory content stored in the domain, and it can change the membership of all administrative groups in the domain. It is the most powerful service administrative group.
Domain Admins
Users container
This group is automatically added to the corresponding Administrators group in every domain in the forest. It has complete control over all domain controllers and all directory content stored in the domain and it can modify the membership of all administrative accounts in the domain.
Server Operators
Builtin container
By default, this built-in group has no members. It can perform maintenance tasks, such as backup and restore, on domain controllers.
Account Operators
Builtin container
By default, this built-in group has no members. It can create and manage users and groups in the domain, but it cannot manage service administrator accounts. As a best practice, do not add members to this group, and do not use it for any delegated administration.
Backup Operators
Builtin container
By default, this built-in group has no members. It can perform backup and restore operations on domain controllers.
DS Restore Mode Administrator
Not stored in Active Directory
This special account is created during the Active Directory installation process, and it is not the same as the Administrator account in the Active Directory database. This account is only used to start the domain controller in Directory Services Restore Mode. In Directory Services Restore Mode, this account has full access to the system and all files on the domain controller.
ref: https://technet.microsoft.com/en-us/library/cc700835.aspx
3) l'appplicazione delle group policies sulle macchine di dominio viene eseguita
a) con le credenziali di localsystem quando si applicano le computer policies ossia allo startup e allo shutdown
b) con le credenziali dell'utente loggato quando si applicano le user policies ossia al login e al logout
ciao.
Edoardo Benussi
Microsoft MVP - Cloud and Datacenter Management
edo[at]mvps[dot]org- Proposto come risposta Edoardo BenussiMVP, Moderator mercoledì 18 gennaio 2017 08:59
- Contrassegnato come risposta Nicola Venosta mercoledì 18 gennaio 2017 09:31