Windows Permission Matrix

Jay_2

2[H]4U
Joined
Mar 20, 2006
Messages
3,583
Do microsoft publish a full permission matrix for built in accounts in AD?

eg

Full list of everything an full admin can do, power user can do etc etc?
 
Sorry I actually wanted a breakdown of what an admin can do in AD, we want this so we can cut down the helpdesk users accounts but I need the matrix first to get it through CAB
 
Sorry I actually wanted a breakdown of what an admin can do in AD, we want this so we can cut down the helpdesk users accounts but I need the matrix first to get it through CAB

By default: Domain Admins can do anything to any machine on the domain.

By default: Local Admins can do anything to the machine they are defined on as an admin.

But I am confused by your question as the two sentences I just wrote are in the information I gave you in the link above.


To create adminstrator (like) accounts with more restrictions you need to use the delegation tools in AD: http://technet.microsoft.com/en-us/library/cc756087(v=WS.10).aspx
 
If you'd like me to copy and paste the answer for you Admins can:


Access this computer from the network

Adjust memory quotas for a process

Allow logon locally

Allow logon through Remote Desktop Services

Back up files and directories

Bypass traverse checking

Change the system time

Change the time zone

Create a page file

Create global objects

Create symbolic links

Debug programs

Force shutdown from a remote system

Impersonate a client after authentication

Increase scheduling priority

Load and unload device drivers

Log on as a batch job

Manage auditing and security log

Modify firmware environment variables

Perform volume maintenance tasks

Profile single process

Profile system performance

Remove computer from docking station

Restore files and directories

Shut down the system

Take ownership of files or other objects
 
Thanks for that, i am talking about AD administration, reset passwords, create ou, delete ou, delegate rights to ou, create groups, add users to group, delete groups etc etc. There are a huge number of things an admin can do in AD. I can actually probably pull it from the delegation menus.
 
Correct Admins can do everything.

You can restrict them in the delegation menu.

As for all the delegation menu options....that's going to be different depending on your version of the server OS.
 
Ok mate, thanks. I'll have a hunt around and see if Microsoft have a full list of delagatable rights in AD for 2008R2.
 
Back
Top