Re: Keep domain admin from being able to take ownership

From: *Vanguard* (no-email_at_post-reply-in-newsgroup.invalid)
Date: 03/31/04


Date: Wed, 31 Mar 2004 14:07:39 -0600


"Russell White" said in news:O7kOtkzFEHA.3764@TK2MSFTNGP12.phx.gbl:
> Greetings.
>
> "Is it possible to make it impossible for a domain admin to take
> ownership of a folder and it's contents?"

No. Instead use EFS. I believe the current owner of the file/folder can dictate who has access *into* an EFS-protected file. The admin users can still take ownership and change permissions but they cannot read the contents of the file. I know that I've done this on Windows 2000 (which assigns Administrator as the default recovery agent whereas Windows XP does not) where my account could read the EFS-protected file but the Administrator could not. Be sure to export the EFS certificate to a floppy and lock it up somewhere.



Relevant Pages

  • Re: lost access to a folder
    ... it is in the computer configuration, security settings, local policies, userright assignments. ... now you should at least be able to Seize ownership. ... (i have experienced not seeing the ACL's when i do not have access to a folder, but if i have the aforementioned right, I always could TAKE ownership and fix everything. ... that a domain admin can always seize ownership. ...
    (microsoft.public.windows.server.general)
  • Re: takeown access denied on w2k3
    ... Neil ... > You didn't mention if you try to take ownership of that folder using ... > domain admin account. ... > ask/guide user to take ownership on their own. ...
    (microsoft.public.windows.server.general)
  • Re: takeown access denied on w2k3
    ... Have you tried to remove that "mysterious" SID from the list of permissions ... >> You didn't mention if you try to take ownership of that folder using ... >> domain admin account. ... >> ask/guide user to take ownership on their own. ...
    (microsoft.public.windows.server.general)
  • Keep domain admin from being able to take ownership
    ... "Is it possible to make it impossible for a domain admin to take ownership ... else can either change permissions, take ownership, ... take ownership of a folder and it's contents? ...
    (microsoft.public.security)
  • "Is it possible to make it impossible for a domain admin to take ownership of a folder and its
    ... "Is it possible to make it impossible for a domain admin to take ownership ... else can either change permissions, take ownership, ... take ownership of a folder and it's contents? ...
    (microsoft.public.win2000.security)

Loading