What is changed in Administrator account upon joining computer to domain?
i developer , clear questions related development environment setup of windows server both in workgroup , in ad .
do understand correctly windows server built-in administrator upon joining domain governed group policies dc , afministrators group added domain admins local administrator cannot delete since pushed (every 90 min) there dc?
on other hand, nothing of possible @ (adding domain user local administrators group or local administrator being governed dc) with "the same" accounts/group (administrator/administrators) in "the same" windows before joining domain.
what determine such disjoint behavior of local administrator account before joining computer domain , after?
what changing in machine account, local administrator user account , local administrators group upon joining domain?
i tried ask in [1] - [9] contradictory each other answers , closing of questions , account (being banned access posts).
what's wrong these questions?
cited:
[1]
domain admins vs. administrators in windows ad dc [closed]
http://serverfault.com/questions/174200/domain-admins-vs-administrators-in-windows-ad-dc-closed
[2]
context of local user of ad-joined machine? of domain machine account or of local machine account?
http://serverfault.com/questions/173550/the-context-of-local-user-of-ad-joined-machine-is-it-of-domain-machine-account-o
[3]
windows workgroup localsystem vs. domain (ad) localsystem [closed]
http://serverfault.com/questions/168763/windows-workgroup-localsystem-vs-domain-ad-localsystem-closed
[4]
workgroup windows users (or groups) can use domain accounts? not vice versa? [closed]
http://serverfault.com/questions/174196/workgroup-windows-users-or-groups-can-use-domain-accounts-but-not-vice-versa
[5]
runas under domain account non-ad windows [closed]
http://serverfault.com/questions/174497/runas-under-domain-account-from-non-ad-windows-closed
[6]
how share same domain machine account multi-boot workgroup windows setup?
http://serverfault.com/questions/168991/how-to-share-the-same-domain-machine-account-with-multi-boot-workgroup-windows-se
[7]
how better set machine development both in workgroup , windows domain? [closed]
http://serverfault.com/questions/169807/how-to-better-set-up-machine-for-development-both-in-workgroup-and-windows-domain
[8]
runas under domain account non-ad windows [closed]
http://serverfault.com/questions/174497/runas-under-domain-account-from-non-ad-windows-closed
[9]
interoperating windows domain computer workrgroup windows [closed]
http://serverfault.com/questions/169142/interoperating-with-windows-domain-computer-from-workrgroup-windows-closed
vgv8,
you want know if anything happens the local administrator account after computer joined ad network, right ? well, answer simple : nothing changes ! have understand first difference between user account , group, before going further. once this, have understand that local user account cannot subject of "user configuration" setting of a domain gpo. he's subject local group policies in place, if exist on computer (like if computer part of workgroup , not domain).
if computer ou in ad , linked ou have 1 or multiple gpo, "user configuration" of every 1 of gpo do not apply local user account. "computer configuration" component of gpo applies computer, if set up. of settings in "computer configuration" of domain gpo do not involve changes of local administrators group in it's functionality. yes, might see the local users accounts (including local administrator account) should change password every x days or have complexity of password no more. might see new domain groups added local administrator group, stops here. none of these change "functionality" of local administrator account. if able edit registry when in workgroup, it'll able edit them after computer joined domain also.
hope 10th thread gave answer looking for.
Windows Server > Directory Services
Comments
Post a Comment