Ya, I knew it just needed to read active directory but I was wondering how people are dealing with Administrative rights on a domain controller without using a domain admin account. When a Server is promoted it loses all of its local accounts so you can't add a local admin for obvious security reasons.