RE: Controlling Admin Access

From: Evan Mann (emann_at_pinnaclefinancial.com)
Date: 02/02/04

  • Next message: Harlan Carvey: "Re: Controlling Admin Access"
    Date: Mon, 2 Feb 2004 11:38:22 -0500
    To: "Michael Cox" <mscox42@yahoo.com>
    
    

    You can remove the admin shares or modify security policy so that access
    from the network is restricted to only the executives, DCs, etc. Modify
    security policy to only let that particular executive login locally and
    that should take care of a domain admin logging in locally and accessing
    files.

    You will still have the ability for a domain admin to reset the password
    and login as the executive themeslves. I don't think there is any
    foolproof way. I recall convos in the past coming up on this in the
    past and there is always the issue of trust and the need to have someone
    in IT to have unrestricted access to all computers for one reason or
    another. What do you do if the executive leaves and all their files are
    in encrypted via a password no one knows?

    -----Original Message-----
    From: Michael Cox [mailto:mscox42@yahoo.com]
    Sent: Friday, January 30, 2004 2:56 PM
    To: focus-ms@securityfocus.com
    Subject: Controlling Admin Access

    I'd like to solicit the group's input on the following.

    Domain administrators, by definition, are going to have complete access
    to member computers.

    Is anyone doing anything to mitigate the potential risks involved with
    access to, say, an executive's computer which could have very sensitive
    data on it (mergers and acquisitions, for example)?

    One obvious answer is encryption, but I'm curious what is available in
    the Windows world as I'm not as familiar with that.

    Even if something like object level auditing was enabled and the logs
    sent to a remote host, couldn't the admin, as a first step, disable this
    logging?

    Please answer both 1) what is possible, and 2) what is your organization
    or other organizations you know of doing about this (if anything).

    Many thanks in advance!

    Michael

    __________________________________
    Do you Yahoo!?
    Yahoo! SiteBuilder - Free web site building tool. Try it!
    http://webhosting.yahoo.com/ps/sb/

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Harlan Carvey: "Re: Controlling Admin Access"

    Relevant Pages

    • Outlook meeting tracking tab not updating acceptances
      ... We have and Executive and Admin using Outlook XP SR-2 with Exchange 5.5 SP4 ... The Admin has delegate permissions to the Executives mailbox. ... requests get sent to the delegates not to the Executive. ... The Admin creates a meeting request for the Executive and sends it to ...
      (microsoft.public.outlook.calendaring)
    • Outlook meeting tracking tab not updating acceptances
      ... We have and Executive and Admin using Outlook XP SR-2 with Exchange 5.5 SP4 ... The Admin has delegate permissions to the Executives mailbox. ... requests get sent to the delegates not to the Executive. ... The Admin creates a meeting request for the Executive and sends it to ...
      (microsoft.public.exchange.admin)
    • Re: [AppArmor 01/41] Pass struct vfsmount to the inode_create LSM hook
      ... writing security policy. ... and install shiny things if they own the box. ... SELinux and AppArmor can't ... That depends who owns the admin password. ...
      (Linux-Kernel)
    • Re: Does Local security policy affect Admin group?
      ... > I have created tight security policy on an XP Pro machine. ... > Can it be locked down without affecting the Admin. ... > would like to lock it down further by not allowing access to the mmc. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: error when trying to get a remote security policy... Please help!!!
      ... admin credentials. ... account may have been removed from the local admin group. ... >> to get the security policy from, infact I have network admin access. ...
      (microsoft.public.win2000.security)