Yesterday and today I (and some other people) were involved in heavy discussion how you can accomplish: Granting Admin level access for the OS on DCs but not within AD The posts can be found in: NG: "microsoft.public.windows.server.active_directory" Post
Read More...