Account operators group in Active Directory

Damien 1 Reputation point
2021-01-14T15:09:55.693+00:00

Hello,

I need to create delegate administration access in Active Directory but i have some difficulties to find the best practise for this.
I've read many posts where answers advised to let Account operators group empty but i never found any explanations about the reason.
Can you explain me where is the risk with that group please ? Can someone escalade to admin account or privilege with this access ?

Thanks !

Sorry for my English ;)

Damien

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,490 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Anonymous
    2021-01-14T15:16:51.193+00:00
    1 person found this answer helpful.
    0 comments No comments

  2. Thameur-BOURBITA 32,831 Reputation points
    2021-01-14T21:48:40.81+00:00

    Hi,
    The idea is to reduce number of the member of group with privilege and add only users who need this high privlege .Because when a account with high privilege compromised , it can make a huge damage.

    I invite you to read this article to get more details about group with high privileage in active directory:

    review-and-reduce-the-number-of-accounts-in-highly-privileged-administrative-groups

    ----------

    Please don't forget to mark helpful reply as answer

    1 person found this answer helpful.
    0 comments No comments

  3. Damien 1 Reputation point
    2021-01-14T17:04:44.077+00:00

    Thank you Patrick.

    I've read this article before but I think I was more confused after reading it than before.

    In the article, Microsoft says in the second paragraph that "Members of the Account Operators group cannot manage the Administrator user account,... Server Operators," and in the purple note that "This group is considered a service administrator group because it can modify Server Operators".
    My english is certainly bad but manage and modify seems to be the same thing, right?

    During my tests, I couldn't be able to change anything in Server Operators group (membership, no Security tab, group scope) when I used my delegate account member of Account Operators.

    If it's the only reason, I have no clues to say it's dangerous in my situation...

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.