RE: Subdomain security

Wim_Remes_at_msp.be
Date: 12/18/04

  • Next message: Hiro Mizutani: "KB824145 with SUS"
    To: "Renouf, Phil" <Phil.Renouf@tdsecurities.com>
    Date: Sat, 18 Dec 2004 22:45:04 +0100
    
    

    Hi,

    First, you were correct when saying that the only true security boundary is
    the forest...but I'm always looking on what I'm trying to secure. There
    are a few reasons to implement seperate forests, there's a million others
    for making extensive use of delegation of authority. In my opinion there
    should only be one single ID that has 'enterprise admin' rights and that
    should be unknown to any normal admin. It should be only used when a change
    to the root domain is required and approved through change management. 99%
    of all daily admin tasks can be performed without domain admin rights, you
    can allow anything to a simple user by using delegation of authority (and
    he won't be able to make himself enterprise admin). with proper ID
    Management and procedures implemented, you would have a dream of a domain,
    not compromising security on any level.

    Changes to the group membership can be ruled out by using a 'restricted
    groups' policy on the domain level.

    there's lots of info about restricted groups around, I'm posting the
    jsiinc.com link cuz JSI has loads of other information (both
    security-related and general) that can help you out on many isssues.

    Regards,

    Wim Remes
    MCSE:Security

    -----"Renouf, Phil" <Phil.Renouf@tdsecurities.com> wrote: -----

    To: "Scott Mulcahy" <scottcm-secfocus@hotmail.com>,
    <focus-ms@securityfocus.com>
    From: "Renouf, Phil" <Phil.Renouf@tdsecurities.com>
    Date: 17/12/2004 19h13
    cc: <oren@held.org.il>
    Subject: RE: Subdomain security

    > I'm fairly certain that an enterprise admin can get admin privs
    anywhere in the forest.

    Not to mention that as a Domain Admin it is very easy for someone to get
    themselves enterprise admin rights. One important thing to monitor is
    changes to the group membership of the major admin groups (Enterprise,
    Schema, Domain etc.). I know that MOM does this pretty well, but I am
    sure other monitoring tools offer that as an option.

    Phil

     ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Hiro Mizutani: "KB824145 with SUS"

    Relevant Pages

    • (no subject)
      ... Look at the Navy-Marine Corps Internet, a contract ... Security is secuirty and penetration means exactly that. ... You just hit a sore spot w/ me...the CSI/FBI survey. ... it's probably an admin who has ...
      (comp.security.misc)
    • (no subject)
      ... Look at the Navy-Marine Corps Internet, a contract ... Security is secuirty and penetration means exactly that. ... You just hit a sore spot w/ me...the CSI/FBI survey. ... it's probably an admin who has ...
      (comp.os.ms-windows.nt.admin.security)
    • Re: Food for Thought
      ... Look at the Navy-Marine Corps Internet, a contract ... Security is secuirty and penetration means exactly that. ... that telling the reader to do a Google search for sources isn't going to ... it's probably an admin who has ...
      (microsoft.public.win2000.security)
    • Re: Grant Administrative Access to a Domain Controller
      ... Anyone with a good understanding of AD and Windows security will easily see ways of compromising the environment. ... Do not give enhanced rights to Domain Controllers to anyone you don't trust with Domain and/or Enterprise Admins. ... Just know that minimal access can be parlayed into even more access and try as you might, you cannot secure Active Directory from people with server operator or admin or several other levels of access rights on a DC. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Rather funny; looks like page defacement to me
      ... > afford one (and often when they can't afford one this person works ... On top of all that pressure, ... so I was a bit caustic on the "incompetent admin" point; ... Nobody would hire me (I'm a security engineer) to draw structural diagrams. ...
      (Focus-IDS)