Re: What is the best way to restrict access to Domain Admins on certain folders?



ACLs won't help to *really* restrict access - Domain Admins can typically
take ownership and change permissions directly or indirectly.

EFS with DRA's that *are not* the Domain Admins but trusted individuals is
the best option off the top of my head. If the DRA and user key pairs and
and associated certificates are properly protected (stored on Smart Cards),
this is pretty much the best it can get without third party components.

Regards,
Dob

--
---
HTH,
Dobromir

Learn more about Security and Identity Management:
Visit http://www.iamechanics.com

"Ravi" <ravichandra.thalluri@xxxxxxxxx> wrote in message
news:bcb0ff16-dced-4ad3-89d0-b866e81b552e@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Some of the folders in our file system contain sensitive financial
data. The file server is managed by our IT department. How do I
restrict the people in Domain Admins group (some of them are from IT
Department) from accessing sensitive data? If I remove read
permissions to Domain Admins, backup jobs may fail


.



Relevant Pages

  • Re: What is the best way to restrict access to Domain Admins on certain folders?
    ... EFS with DRA's that *are not* the Domain Admins but trusted individuals is ... Learn more about Security and Identity Management: ... Department) from accessing sensitive data? ...
    (microsoft.public.security)
  • Re: ASP.NET - Windows Authentication Problem
    ... to change it if I am going to restrict access to only a certain Active ... >> I am having a problem with my ASP.NET application and using Windows ... >> permissions. ... Then it won't let anyone in, including the domain admins ...
    (microsoft.public.dotnet.security)
  • RE: Delegation of rights issue
    ... gowfmt, you can really restrict access even to Domain Admins, so, you can get ... a "gray" status in objects. ... this is not a recommendation procedure; ...
    (microsoft.public.windows.server.active_directory)
  • RE: Restrict the Domain Admin
    ... I truly didn't trust any of my domain admins (playing with fire, ... environment will NEVER be trustworthy with these types of people around). ... How much you can give the non-built-in admin group you create, ... > Is there a way to restrict access of a Domain Admin? ...
    (Security-Basics)
  • RE: Restrict the Domain Admin
    ... you would delegate permissions using GPO's in Active Directory instead of making them Domain Admins. ... This way you can be as granular as you want when assigning admin chores, ... Is there a way to restrict access of a Domain Admin? ...
    (Security-Basics)