RE: Creating/editing user accounts

From: Al Miller (al@amicas.com)
Date: 11/08/01


Subject: RE: Creating/editing user accounts
Date: Thu, 8 Nov 2001 15:04:35 -0500
Message-ID: <DCC18B9DD1E17247A9CB2B1D5B74E80A3033@NEW-AMI-MAIL-01.amicas.com>
From: "Al Miller" <al@amicas.com>
To: "Derek T" <sigmafive@hotmail.com>, <focus-ms@lists.securityfocus.com>

You can designate an OU for these user accounts and delegate control of
the OU to whomever you like. Anyone can add and edit user accounts they
just need to be given the appropriate permissions.

-----Original Message-----
From: Derek T [mailto:sigmafive@hotmail.com]
Sent: Thursday, November 08, 2001 12:11 PM
To: focus-ms@lists.securityfocus.com
Subject: Creating/editing user accounts

A quick question about AD and web enabled services.

The company I work for is trying to offer the ability to open and
manipulate
accounts from the Web ( kind of like Yahoo or Hotmail). The problem lies
in
the choice to use AD on the segmented network. With AD the only ID with
the
rights to create and edit user accounts are sys-admins, something that
you
can not allow anonymous web browsers to assume. Also this will be a
branch
off the main corporate network, ( in it's own DMZ) to allow customer
service
reps to access and work with the same data from the main tree. Any ideas
on
how can this be accomplished and kept secure, or is it a pipe dream?

Also in the event that a process is given the Sys-admin rights instead
of a
user, what potential security implications does this pose? It seems as
if
almost every discussion of a new vulnerability starts with " You see,
there
was this process running with administrator rights...." =)

Thanks for the insights

D True

"If debugging is the process of removing software bugs, then programming

must be the process of putting them in."- L. Owando

_________________________________________________________________
Get your FREE download of MSN Explorer at
http://explorer.msn.com/intl.asp



Relevant Pages

  • Creating/editing user accounts
    ... Subject: Creating/editing user accounts ... A quick question about AD and web enabled services. ... the choice to use AD on the segmented network. ... Also in the event that a process is given the Sys-admin rights instead of a ...
    (Focus-Microsoft)
  • Re: Creating/editing user accounts
    ... Subject: Creating/editing user accounts ... You can *very* easily delegate the ability to create and edit user accounts ... without giving admin rights in AD. ... you should not be giving administrative rights to accomplish ...
    (Focus-Microsoft)