Home › Active Directory users and groups › Step 7

Default administrative groups in Active Directory

Step 7 of 9 in Active Directory users and groups · video 6:42

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Windows Server creates many groups on its own: local groups such as Administrators, Backup Operators and Remote Desktop Users, and in a domain further groups in the Builtin and Users containers. This lesson concentrates on the ones with administrative power. Enterprise Admins and Schema Admins exist only in the forest root domain; Administrators, Domain Admins, Server Operators, Account Operators, Backup Operators, Print Operators and Cert Publishers exist in every domain. For each group the video explains what its members can do, for example that Domain Admins is added to the local Administrators group of every domain member and that Account Operators can manage most accounts and even sign in to domain controllers. It then introduces protected groups: their members stop inheriting permissions from their OU, so a help desk with password-reset rights cannot reset them. The advice is to leave the operator groups empty and build custom groups with only the rights needed.

Good to know: members of protected groups receive their permissions from the AdminSDHolder object, which the SDProp process reapplies every 60 minutes by default.

Check yourself

Answer in your head first, then open each question to see the answer.

1. In which domain and container is the Schema Admins group created?

In the Users container of the forest root domain only. There is one Schema Admins group per forest because every domain in the forest shares the same schema.

2. How do members of Domain Admins end up with administrative rights on every domain-joined workstation?

When a computer joins the domain, Domain Admins is added to its local Administrators group by default. Its members therefore administer every domain member computer.

3. The help desk can reset passwords for every user in the Employees OU except one, who was recently added to Account Operators. Why?

Account Operators is a protected group. Its members stop inheriting permissions from their OU and receive the protected ACL instead, so the help desk's delegated reset right no longer applies to that account.

4. A user must back up domain controllers but must not restore them or shut them down. Why not add him to Backup Operators, and what should you do instead?

Backup Operators can also restore data and shut down domain controllers, which is more than he needs. Create a custom group granted only the Back up files and directories user right, and add him to it through a global group.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Managing Groups, Computers and OUs

4.5★ · 1,445 students on Udemy

See the course on Udemy
← Group nesting with IGDLA and IGUDLANext: Special identities in Windows and AD DS →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.