Home › Active Directory users and groups › Step 7
Default administrative groups in Active Directory
Step 7 of 9 in Active Directory users and groups · video 6:42
What you will learn
- Which default admin groups live in the forest root and which in every domain
- What Domain Admins, Account Operators and Backup Operators can actually do
- How protected groups change permissions on their members' accounts
- Why custom groups are better than the built-in operator groups
About this lesson
Windows Server creates many groups on its own: local groups such as Administrators, Backup Operators and Remote Desktop Users, and in a domain further groups in the Builtin and Users containers. This lesson concentrates on the ones with administrative power. Enterprise Admins and Schema Admins exist only in the forest root domain; Administrators, Domain Admins, Server Operators, Account Operators, Backup Operators, Print Operators and Cert Publishers exist in every domain. For each group the video explains what its members can do, for example that Domain Admins is added to the local Administrators group of every domain member and that Account Operators can manage most accounts and even sign in to domain controllers. It then introduces protected groups: their members stop inheriting permissions from their OU, so a help desk with password-reset rights cannot reset them. The advice is to leave the operator groups empty and build custom groups with only the rights needed.
Check yourself
1. In which domain and container is the Schema Admins group created?
In the Users container of the forest root domain only. There is one Schema Admins group per forest because every domain in the forest shares the same schema.
2. How do members of Domain Admins end up with administrative rights on every domain-joined workstation?
When a computer joins the domain, Domain Admins is added to its local Administrators group by default. Its members therefore administer every domain member computer.
3. The help desk can reset passwords for every user in the Employees OU except one, who was recently added to Account Operators. Why?
Account Operators is a protected group. Its members stop inheriting permissions from their OU and receive the protected ACL instead, so the help desk's delegated reset right no longer applies to that account.
4. A user must back up domain controllers but must not restore them or shut them down. Why not add him to Backup Operators, and what should you do instead?
Backup Operators can also restore data and shut down domain controllers, which is more than he needs. Create a custom group granted only the Back up files and directories user right, and add him to it through a global group.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.