RE: AD Question

From: Brian W. Spolarich (bspolarich_at_nephrostherapeutics.com)
Date: 05/01/03

  • Next message: Arnold, Jamie: "RE: Outlook Security Settings removed"
    Date: Thu, 1 May 2003 08:52:43 -0400
    To: <drivero@decidir.net>, <focus-ms@securityfocus.com>
    

    Diego Rivero - Decidir IT wrote:
    > Hi, I have a question.
    >
    > I want to assign administrators rights to a user domain in a machine
    > running W2K Server, the problem is that the machine is domain server,
    > I dont want to make that user member of the domain admin group, He
    > only needs to have administrators rights on the local machine.

      This is not possible. By promoting the machine to become an Active Directory Controller (ADC), you effectively replace the local SAM database with the domain one. ADCs have no local SAM, and all local machine accounts become domain accounts.

      When you promote a machine you will be prompted to specify an "Active Directory Services Restore Mode" password or somesuch. This is essentially the password for the local Administrator acccount that will be used if/when you demote the machine back to a normal domain "member server" sometime in the future. But while the machine is an ADC, it only has domain accounts.

      The intended deployment model for ADCs is to have them be on dedicated hardware that is only used for providing ADC and similar infrastructure services (i.e. Internet Authentication Services, DNS, etc). That's obviously not always practical is very small deployments, so you'll either have to live with the security exposures, or deploy additional hardware to isolate your ADC hosts from the rest of your network functions.

      -bws

    -----------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s most
    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------------


  • Next message: Arnold, Jamie: "RE: Outlook Security Settings removed"

    Relevant Pages

    • AD Question
      ... I want to assign administrators rights to a user domain in a machine running ... W2K Server, the problem is that the machine is domain server, I dont want to ... prospectus based upon the core principle concepts of security. ...
      (Focus-Microsoft)
    • Re: Event 861 fills event log on newly built Domain Controller
      ... Event Source: Security ... Event Category: Detailed Tracking ... User domain: NT AUTHORITY ...
      (microsoft.public.windows.server.active_directory)
    • windows update installs and installs and
      ... Windows updater downloaded and installed a security ... time I restart the PC, I am told the same update has been ... reappearing. ... I am using Home XP with administrators rights ...
      (microsoft.public.windowsxp.security_admin)