How to prevent my users based on domain name

manavalan R 101 Reputation points
2021-04-07T15:16:45.197+00:00

Hi all, I have one master domain controller called "domain.com" and have two child domain called "child1.domain.com" and "childtwo.domain.com" and also joined the windows 10 machine to the master domain controller "domain.com" and then i have add users on the client windows machine by choose the location "domain.com" or its child domain.

My question is, for domain based i need give promote any user from domain.com as admin role in client windows 10, same as to other sub-domain users. If any domain based admin user can't delete the other domain's admin and users.
Which mean domain based privileges.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,770 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,899 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-04-08T08:12:59.543+00:00

    Hi,
    First of all , let make sure the difference between domain admins and enterprise admins in parent domain (root domain).

    Domain Admins:
    Members of this group have full control of the domain. By default, this group is a member of the Administrators group on all domain controllers, all domain workstations, and all domain member servers at the time they are joined to the domain. By default, the Administrator account is a member of this group. Because the group has full control in the domain, add users with caution.
    Enterprise Admins (only appears in the forest root domain)
    Members of this group have full control of all domains in the forest. By default, this group is a member of the Administrators group on all domain controllers in the forest. By default, the Administrator account is a member of this group. Because this group has full control of the forest, add users with caution.

    So a admin in the Domain Admins: in the parent domain will not have the permission to deletes users in child domain.
    But admins in the Enterprise Admins will have the full permission to controller the child domain, include delete users in child domain.
    Best Regards,


5 additional answers

Sort by: Most helpful
  1. Muhammad Safeer Saqib 1 Reputation point
    2022-12-01T05:41:57.397+00:00

    Hi,

    I have a question I have three different sites Norway, the USA, UK, and I have installed ADDC xyz.com in Norway datacenter and AADDC in the USA,UK.

    Now my requirement is that USA users authenticate from AADDC installed in the USA data center. Please advise and Guide.

    0 comments No comments