We have an unfortunate situation in that we have a domain with regional sites (80). Each has a "branch server" which is a domain controller. Our Network dept have to be able to "SMS in" and perform certain other tasks on these machines.If they were member servers we could use local groups but not with DC's.
Unfortunately however much we have tried we figure we are going to have to let this dept stay in Administrators group for the Domain (eek!).
Our problem is they definitely shouldnt be performing user management. Does anyone know of a way to stop Admins doing such things (we can think of any) or at very least know of any monitoring tools to allow us to see who has made which changes to users ?????
Unfortunately however much we have tried we figure we are going to have to let this dept stay in Administrators group for the Domain (eek!).
Our problem is they definitely shouldnt be performing user management. Does anyone know of a way to stop Admins doing such things (we can think of any) or at very least know of any monitoring tools to allow us to see who has made which changes to users ?????
Comment