Hello –
I am looking for your suggestions/thoughts/best practices for delegating administrative rights within Active Directory and in general.
I have a Junior Admin starting shortly who’s position can best be described as an IT generalist. The scope of work will encompass everything from new user creation/user management in AD to printer management, share management, etc. I will not be giving out the domain admin password or domain admin rights to his user account. I was planning on creating a security group that includes his user account and delegating right from there.
I would like him to be able to log into certain servers (File server/app server/etc) to monitor drive space and work with apps but don’t want him working on the DCs/Exchange/etc. Would it be best to set the new security group as a Server Operator on the desired servers?
Any thoughts, suggestions, pitfalls, etc would be greatly appreciated.
Thanks,
Tyler