Re: How to restrict changes to Domain Admin & Administrator Groups



Stan wrote:
Is there a way to protect W2003 AD Domain Admin & Administrator
Groups so existing members cannot add other users to these groups ?

I only want our Enterprise Admins group to have change rights to
these groups.

I have tested

Created OU- Test,
Removed write permission for domain admins on this Test OU.
Blocked inheritance with exception of Enterprise Admins
Then moved Domainadmin group to this OU,
Removed write permission and removed self as member for this group
But after 1 hr all the settings are rolled back..

If this is not possible and Micirsift does not recommend this can
you point me to MS Documentation

I need to show our auditors this kind of change is not possible.

Who cares about the auditors at this point?

If you have domain admins/administrator group members you cannot trust with
the power this gives them - they should not be in those groups at all.
That's a social/political issue - not a technical one.

Don't complicate a simple problem - those who cannot be trusted with extra
privs do not get extra privs.

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


.



Relevant Pages

  • Re: problem with "Restricted Groups" within a GPO linked to my dom
    ... You are saying that the users no longer appear as members of the RG but the ... logon again if you are using the test user account so that their security ... > groups: Administrators, Backup Operators ... > Domain Admins, Enterprise Admins ...
    (microsoft.public.security)
  • Re: Container Administration where you can block out Enterprise Admins
    ... Hi Samuel, Enterprise Admins are a very power full group, Members of this ... by this is don't think the way of restrict members of the Enterprise Admins ... In your case use the Delegate Of Control Wizard to delegate rights to threes ...
    (microsoft.public.win2000.active_directory)
  • Re: Blocking "Enterprise Admins" permissions
    ... You can not* restrict Enterprise Admins Group and should not do so, ... How ever if you not trust the members of the enterprise ... should only select member that you trust to be Enterprise Admins. ...
    (microsoft.public.win2000.active_directory)
  • Re: Separating domain admins and enterprise admins
    ... it is IMPOSSIBLE to prevent members of administrators, domain admins and enterprise admins doing things you do not want them to do! ... * This posting is provided "AS IS" with no warranties and confers no rights! ...
    (microsoft.public.windows.server.active_directory)