Hi -
We have a domain where Domain Admins do not have local admin on every system in the domain, only on DC's. We have created a separate group that has local admin everywhere, which is where my SCCM service account has membership. I can deploy clients and updates/apps, etc. to all my clients just fine, I just can't manage the Domain Controllers now under this setup.
Is there a way to separate management of collections or deployments out to different accounts? This is a pretty common security posture so I gotta believe there's a way..
We have a domain where Domain Admins do not have local admin on every system in the domain, only on DC's. We have created a separate group that has local admin everywhere, which is where my SCCM service account has membership. I can deploy clients and updates/apps, etc. to all my clients just fine, I just can't manage the Domain Controllers now under this setup.
Is there a way to separate management of collections or deployments out to different accounts? This is a pretty common security posture so I gotta believe there's a way..