Delete Domain admins from local administrators group on member server

LULU 221 Reputation points
2022-03-13T19:50:29.33+00:00

Hi,

By default the domain admins group is added by default in local administrators group.
Our security team ask us to remove it from local administrators group.

My question is : There is any impact if we perform this action ?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,449 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,368 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,108 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,838 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 32,496 Reputation points
    2022-03-13T19:58:07.407+00:00

    Hi,

    If the Security teams want implement the 3 tiers administration model , it's recommended to remove domain admins group on local administrators on each server and computer in tiers 1 and tiers 2.

    To get more details about 3 tiers model you can refer to the following link : use-microsofts-active-directory-tier-administrative-model

    Before performing this action , you should check if there is any service account member of domain admins already used to run a scheduled task or service in member server.

    Please don't forget to mark helpful reply as answer

    0 comments No comments

0 additional answers

Sort by: Most helpful