How to monitor "domain controllers" without domain admin rights



I hope someone can help me. I manage a fairly large active directory
environment and I'm trying to lock things down to prevent security breaches,
etc. We use various monitoring utilities to monitor all servers (including
DCs) and I'm finding it very difficult to use any of these programs without
breaking my security.

Almost every one of them need domain administrator rights. Well that's not
true, but let me clarify. I stripped the security of the service accounts we
use and created groups to add these service accounts as local admins on the
various servers.

My problem is now specifically with DCs. I don't want these service
accounts to have full administrative privileges on my DCs or Active
Directory. As such I don't want to add these accounts to the built
in\administrators group as they will get these rights. I have successfully
opened up WMI onto these DCs, but am finding my tools use a variety of ways
to run their monitors and they are not all via WMI. For example, some of
these tools check disk space by hitting the root admin share of each drive
(i.e. c$). I can't change permissions on this.

What do I do? Is there a way to give these accounts the rights I need, but
prevent them from actually logging on locally to the DC and prevent them from
making changes in AD?

Do I just bite the bullet here and just make it a domain admin account with
super crazy pw?

TIA!
MCDONAMW
.



Relevant Pages

  • Re: hide organizational unit from view in active directory
    ... The security of a security principal isn't supposed to be in its identifier, it comes from the authenticator (password/certificate/biometric/etc). ... As for hiding the admin accounts, I have yet to have seen a good valid ... Author of O'Reilly Active Directory Third Editionwww.joeware.net ...
    (microsoft.public.windows.server.active_directory)
  • RE: [fw-wiz] Architecture Q - Public access domain integrated pc s
    ... security within Active Directory, utilizing Group Policy objects. ... the Group Policy editor, there are configurations for user accounts policy, ... there are some good starting points for GPO security at the ...
    (Firewall-Wizards)
  • Re: external server authentication and licensing
    ... It is a booking system so security is an issue. ... Its just really convenient if you already have all these accounts and ... have any trouble with active directory, ...
    (comp.databases.filemaker)
  • Re: hide organizational unit from view in active directory
    ... Anything else is a huge security no no. ... As for hiding the admin accounts, I have yet to have seen a good valid ... Author of O'Reilly Active Directory Third Editionwww.joeware.net ...
    (microsoft.public.windows.server.active_directory)
  • Re: Integrated security - why not?
    ... Let me explain why we seldom use Integrated Security for Internet asp.net ... how could we setup accounts for them? ... !server to the public network with services such as SQL Server (remember SQL ... The DC at the ISP is not for our own use. ...
    (microsoft.public.dotnet.framework.aspnet.security)