Re: Threat vector of running a service using a domain account



Are the users admins on their own machines? If so, a login script to
add permissions for another group (LocalServiceAccounts, perhaps?)
would work.

Otherwise, a policy to add the AD group to the local Administrators
group would probably work well.

On 9/12/07, Ali, Saqib <docbook.xml@xxxxxxxxx> wrote:
I can't reveal the name of the application, but it is 3rd party non-MS
application.

The reasons it puts itself in the Domain Admin group is that it needs
administrative access to the client computers. And Domain Admin group
is part of the Local Administrator group on all client computers it
works out nicely.

saqib
http://security-basics.blogspot.com/




Relevant Pages

  • Re: To those who designed Group Policy in Active Directory
    ... >> policy to your domainand a stricter password policy ... >> IT or Domain Admin group, which has to be applied to the domain level as ... Because the USER ACCOUNT PASSWORD has something to ... was that of the OU not at the domain level. ...
    (microsoft.public.windows.server.active_directory)
  • Re: To those who designed Group Policy in Active Directory
    ... > policy to your domainand a stricter password policy ... > IT or Domain Admin group, which has to be applied to the domain level as ... > and put all the computers that belong to IT staff to put into one specific ... > I put all the IT accounts in an OU and also move the IT group to that OU ...
    (microsoft.public.windows.server.active_directory)
  • Re: ask your advice.
    ... If you want to lock down your TS-servers real good then create a OU which doesn't have the hardening policy so that you can clean the server from those settings before you need to do administrative tasks like install programs etc. ... R2 SP2 terminal server? ... policy to deny applying to the domain admin group, ...
    (microsoft.public.windows.group_policy)
  • "Access Denied" when adding workstation to domain
    ... I modify the Default Domain Security Policy, Domain Controller Security ... I also attempted to do the same as above for a single user, ... create/delete computer objects without leaving them in the domain admin group? ...
    (microsoft.public.windows.group_policy)
  • Re: Threat vector of running a service using a domain account
    ... The reasons it puts itself in the Domain Admin group is that it needs ... is part of the Local Administrator group on all client computers it ...
    (Security-Basics)