Hi,
I am currently reading the MS Press book Upgrading your certification to Windows 2003 (ISBN 0-7356-1971-9) and I am a bit confused about the part about demoting a Domain Controller on page 2-16. It states that certain group membership is required to remove Active Directory:
"To remove Active Directory from a system that is the last domain controller in any domain except the forest root, you must be a member of the Enterprise Admins group"
"To remove Active Directory from the last domain controller in a forest, you must be a member of the Domain Admins group"
If I understand correctly you "only" have to be a member of Domain Admins to remove the forest (last domain controller in a forest) but you'd need to be a member of Enterprise Admins to remove a domain from a forest. I expected this to be the other way around. Can someone explain the deeper thought behind this????
thanks,
Jeffrey
I am currently reading the MS Press book Upgrading your certification to Windows 2003 (ISBN 0-7356-1971-9) and I am a bit confused about the part about demoting a Domain Controller on page 2-16. It states that certain group membership is required to remove Active Directory:
"To remove Active Directory from a system that is the last domain controller in any domain except the forest root, you must be a member of the Enterprise Admins group"
"To remove Active Directory from the last domain controller in a forest, you must be a member of the Domain Admins group"
If I understand correctly you "only" have to be a member of Domain Admins to remove the forest (last domain controller in a forest) but you'd need to be a member of Enterprise Admins to remove a domain from a forest. I expected this to be the other way around. Can someone explain the deeper thought behind this????
thanks,
Jeffrey