Domain Controller Local Admin Group
When you promote a computer to a domain controller the local authentication repository is used to store domain accounts.
Domain controller local admin group. Membership can be modified by members of the service administrator groups in its domain administrators and domain admins and by members of the enterprise admins group. If you have a domain trust setup you can also add accounts from other trusted domains. Under log on as select the this account option.
We often find that a servers gpo is also linked to the domain controllers ou and it adds a server admins group to the local administrators group. How to add domain group to local administrators group. In all honesty having local users on a.
Since domain controllers don t have a local administrators group the dc updates the domain administrators group by adding server admins. This will grant local permissions to the. Click browse type the name of an account that is a member of the domain admins group click check names and click ok.
This can be accomplished by having an active directory group with all administrators domain accounts added to it and then add this group to the local admin group on each of the host. Since there is no longer a set of local users groups etc. Click ok three more times.
Open elevated command prompt. Within active directory search for your builtin administrators group and add your service or user account into that group. From an administrative command prompt you can run net localgroup administrators add domain user without the brackets.
Local administrator may not be a good group to add users to on a domain controller however for other purposes like event log reader and the like this worked well. This is considered a service administrator account because its members have full access to the domain controllers in a domain. This scenario makes all members of server admins active directory admins.