RE: Deny Logon by Domain Admin account to specific PC's or deny to all BUT specific PC's

From: Laura A. Robinson (larobins_at_bellatlantic.net)
Date: 11/11/05

  • Next message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: What server hardening are you doing these days?"
    Date: Thu, 10 Nov 2005 21:30:48 -0500
    To: "'Hindle, Dallas'" <Dallas.Hindle@bakersdelight.com.au>, <focus-ms@securityfocus.com>
    
    

    Well, you can do this with Group Policy, but it's really going to depend on
    your OU structures. Assuming all of the machines/software using this account
    are servers, do you have your servers in a single OU structure? If this is
    the case, I can give you more information, but it's gonna be a lot of typing
    if this isn't the case, so I'll wait for your reply. :-)

    Laura

    > -----Original Message-----
    > From: Hindle, Dallas [mailto:Dallas.Hindle@bakersdelight.com.au]
    > Sent: Thursday, November 10, 2005 8:16 PM
    > To: focus-ms@securityfocus.com
    > Subject: Deny Logon by Domain Admin account to specific PC's
    > or deny to all BUT specific PC's
    >
    >
    >
    > Hi all
    >
    >
    >
    > I assumed this was easy but I must be missing something...
    >
    >
    >
    > I have a domain admin Account that is used for Services, SQL
    > Processes, Scheduled Tasks and for automated logons for some
    > proprietary software... This account has had the password
    > leak out to a 3rd party whom has decided to share it with
    > other people in the company.
    >
    >
    >
    > As I'm sure you agree I need to get his account locked down
    > ASAP, I want to prevent logon to this account from any pc's
    > other than the ones I authorise, and I though this was a
    > simple process, I don't know what I'm missing but if anyone
    > has any suggestions it would be much appreciated.
    >
    >
    >
    >
    >
    >
    >
    > Thanks
    >
    >
    >
    > Dallas
    >
    >
    >
    >
    >
    >
    >
    >
    > --
    > Message protected by MailGuard: e-mail anti-virus, anti-spam
    > and content filtering.
    > http://www.mailguard.com.au/mg
    >
    >
    >
    > --------------------------------------------------------------
    > -------------
    > --------------------------------------------------------------
    > -------------
    >

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: What server hardening are you doing these days?"

    Relevant Pages

    • [EC-SA-01.2003] Windows XP "welcome screen" exposes the names of all the members of the l
      ... logon screen with what is called "Welcome Screen". ... (including the original administrator account, ... Using the "welcome screen" actually disables / ignores the security ...
      (Bugtraq)
    • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
      ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
      (microsoft.public.windows.server.sbs)
    • Re: Is it really true that NTFS is secure?
      ... > and failure auditing starting with "Audit Account Management," and also try ... > The account Group got put back in the Administrator group again. ... > The logon to account: ...
      (microsoft.public.security)
    • Re: Please help refresh my memory on AD DC
      ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here ... admin account to be able to Login so I can control it from the DC. ... A domain user can by default logon to any domain computer, except Domain controllers. ... A Server has websites already hosted on it in a Workgroup and now I ...
      (microsoft.public.windows.server.active_directory)
    • Re: Logon Server Unavailable
      ... >> More Connections Can Be Made At This Time ... >> The network folder specified is currently mapped using a different user ... >> account in its primary domain is missing or the password on that account ... >> There are currently no logon servers available to service the logon ...
      (microsoft.public.windows.server.dns)