Dracula28 wrote: There are no local users and groups on a domain controller. Domain admins can always connect remotely to servers and workstations in the domain, because local administrators (and remote desktop users) have the user right "log on through terminal services" on member servers/XP clients. Since Domain admins are added to the local administrators group on all computers that are joined to the domain, therefore they have that user right as well. So you do not need to add domain admins to any group, all you need to do is to enable remote desktop on the server/XP client. Good luck with your preparations.