My first question is why you want a user to have access to your DC at all?
Regular user shall never need to logon to a DC. Do the work for him and
don't let him to logon, he may do something with the DC which can result in a
disaster and cause huge problems for you and your company...I've seen this
before so my recomendation is that you do the work on the DC's and don't let
any user into your DC's.
--
Henrik
MCSE - Windows Server 2003 + MCP
"Aref" wrote:
> I have a domain in branch office. I need to let a domain user to login
> to this DC but not have the previlages to change to domain objects
> like add users and change password, just add printer and server
> operation.
>
>
|