Is there a way to get up an account that can roam the system with Domain Admin rights but NOT be allowed to change anything? We have recently outsourced and we wish to be able to check on what is happening on the system without being accused of 'meddling' with the system.
Create a new account, then assign or delegate to it only the read rights over all the AD containers and objects. This is done through Active Directory Users and Computers.
Additional Expert Help:
Be sure to check our Answer FAQ for more expert advice.
For faster answers, visit ITKnowledge Exchange.
This Content Component encountered an error
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.