ACL Issue - Easy Question

From: Tom Baker (tdbaker@hotmail.com)
Date: 08/09/02


From: "Tom Baker" <tdbaker@hotmail.com>
Date: Fri, 9 Aug 2002 11:18:13 -0400


Hello Everyone,

I have a situation where a few people need to be in the Administrator group
on the DC's in our domain. What we do not want the mto be able to do is add
either themselves or other people to the Domain Admins or Enterprise Admins
group. My assumption is that I can go to the security tab on each of these
objest and remove the the WRITE and Add Self permissions from the
Administrators groups set of permissions. I just want to make sure that as
soon as I do that, my weekend in going to be spent restoring AD because I
have screwed the system up.

Any feedback would be appreictaed.

Tom Baker



Relevant Pages

  • Security Issue
    ... I removed domain admins from the local administrator group ... of a member server and they are denied access to ...
    (microsoft.public.win2000.security)
  • Re: ACL Issue - Easy Question
    ... In article, Tom Baker ... > I have a situation where a few people need to be in the Administrator group ... > either themselves or other people to the Domain Admins or Enterprise Admins ... > objest and remove the the WRITE and Add Self permissions from the ...
    (microsoft.public.win2000.security)
  • Re: Domain Admin group in ISA 2006
    ... If you can't trust the Domain Admins then the war is already over and you lost. ... ISA would be the last thing you have to worry about. ... subsequently remove Domain Admins from having the ISA Server Full ...
    (microsoft.public.isaserver)