For companies that are very busy and do not have time to do this, there is a Built-In Group called Account Operators which is always overlooked by Administrators. In face this group is perfect for help desk staff, here is why:
Account Operators is a domain local group that grants limited account creation privileges to a user. Members of this group can create and modify most types of accounts, including those of users, local groups, and global groups. They can also log on locally to domain controllers. However, Account Operators can't manage the Administrator user account, the user accounts of administrators, or the group accounts Administrators, Server Operators, Account Operators, Backup Operators, and Print Operators. Account Operators also can't modify user rights.
After reading this I encourage you to take your help desk employees out of the Domain Admins group and add them to the Account Operators group, it will allow them to perform most elements of their service desk duties.

No comments:
Post a Comment