Re: RE: Restricting the change of the local administrator account password.

From: Rob O'Connell (oconnellr_at_cox.net)
Date: 05/07/04

  • Next message: Focus-ms: "Re: Msg reply"
    To: "Depp, Dennis M." <deppdm@ornl.gov>, Ansgar -59cobalt- Wiechers <bugtraq@planetcobalt.net>, focus-ms@securityfocus.com
    Date: Fri, 7 May 2004 8:05:15 -0400
    
    

    > Another option is to create a policy
    > that prevents them from doing so. If they disobey the policy they loose admin rights.
    >
     My feeling watching this thread was that a documented policy was the way to go, it doesn't seem like a technical solution will suffice. Many organizations mandate that Domain Admins restrict their own access to specific OUs, Servers etc. that house financial data, or information that must be kept anonymous to comply with Privacy laws. Really the only way to accomplish this is a regular compliance check from a third party like Legal or HR. It should be understood by the Admins in question that serious consequences will follow if they are found to have changed the admin password.

    Rob.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Focus-ms: "Re: Msg reply"

    Relevant Pages

    • RE: Compile Audience error
      ... \par Hi Rob, ... \par If this policy is not defined at the active directory, then this suggestion will not apply. ...
      (microsoft.public.sharepoint.portalserver.development)
    • Re: Domain Admin disabled
      ... host with -n 100 then I activated the account aagain. ... > my 2 domain admin account are disabled. ... > policy is forced immediately, and I was only lucky the first time. ...
      (microsoft.public.windows.server.general)
    • Re: Tin Foil Helmets on...
      ... Ahem A Rivets Shot wrote: ... confirm/deny/explain this policy, but I, for one, am somewhat pissed off ... Rob - Shropshire ...
      (uk.rec.sheds)
    • Re: Jim Lee, Marc Silvestri, Whilce Portace, Rob Liefeld...
      ... (apart from Rob) their ART was gorgeous. ... policy that followed their success that screwed everything up. ...
      (rec.arts.comics.marvel.xbooks)
    • Re: Preventing Right-Click on Desktop
      ... Rob B. schrieb: ... Microsoft MVP - Windows Server - Group Policy. ... Use a newsreader! ...
      (microsoft.public.windows.group_policy)