Re: full sharing between domain admins

From: Steven L Umbach (n9rou_at_attbi.com)
Date: 04/29/03


Date: Tue, 29 Apr 2003 01:19:15 GMT


        Senol. They could also remove the domain administrator from the
administrators group on their machine and add themselves, however as Jason
mentions a determined domain administrator ultimately has ways to gain
control again of any domain machine - using restricted groups would put
themselves back in local administrators group for instance. Solution may be
to remove their computers from the domain or possibly use third party
encryption tool to encrypt sensitive data (EFS can be accessed by domain
administrator via recovery agent) --- Steve

"Jason Garms [MS]" <jasong@microsoft.com> wrote in message
news:01d001c30dc6$2d939c00$a501280a@phx.gbl...
> Hi Senol,
>
> In general, it's not a good practise to have your domain
> admins logon to workstations as domain admins all the
> time. They should have 2 accounts -- one they use for
> daily activities, such as logging on to workstations,
> reading email, surfing the web, writing documents; and a
> second account that is a domain administrator that is only
> ever used to perform administrative functions. Then the
> user can use "secondary logon" (runas) to perform
> administrative actions with his/her administrative account.
>
> Also, to your specific question about denying them access
> to the adminsitrative share of other domain admins, it's
> ultimately a lost cause, since domain admins are in fact
> ultiamtely domain admins, and as long as the workstations
> are part of the domain, a domain admin can do things to
> get access to it. However, you could achieve your request
> by adding the other domain admin accounts to the "deny
> network access" user logon rights. However, this will not
> only prevent them from accessing the adminsitrative
> shares, but also any share, and other networking function.
> Just realize that a deteremined domain administrator could
> still change this -- by using group/domain policy.
>
> best,
> -jasong
>
> >-----Original Message-----
> >We have a domain with more than one domain admins. Every
> domain admin has
> >individual pc's. If an admin logons to his/her individual
> pc with his/her
> >admin account then they have full acess to others'
> default admin shares. We
> >want to prevent this default full sharing between domain
> admins. How can we
> >do?
> >
> >
> >.
> >



Relevant Pages

  • Re: Domain Admin .vs Adminstrator Account
    ... THE Administrator account is the initial or default ... > However, the domain admins group is automatically added to the local> administrators group on all domain members, which means that> the domain admins account has full administrative control over all domain> member machines. ... The administrator account on the other hand, isn't as> powerful in this way (just being an administrator of the domain doesn't mean> you can install software on domain members); the administrator account is> much more powerful, as Cary already stated, from a domain administrative> stand point. ...
    (microsoft.public.win2000.active_directory)
  • Re: Roaming Profile problem
    ... Unless you're playing with Restricted groups policy or any other scripts, generally Domain Admins are members of local Administrators in all machines in the domain check that. ... I did log on as the domain administrator not the local admin. ... You're logged on with the account that refer to the profile to be copied. ... Logged on as test student ...
    (microsoft.public.windows.server.active_directory)
  • Re: Possible answer to domain problems
    ... that the DCPROMO process may change the policy so that only domain admins ... local administrator when running DCPROMO, so that if the Domain Admins group ... > install Office XP on it, so I started from scratch again. ...
    (microsoft.public.win2000.security)
  • Re: Delegating people as Administrators of a DC
    ... Members of the domain local Administrators group have the same level of ... privileges as far as Active Directory is concerned as Domain Admins. ... Administrator role separation capability has been introduced in Windows ... to domain controllers to only those members of IT staff that you can trust ...
    (microsoft.public.windows.server.active_directory)
  • Re: XP security
    ... > administrator can access his computer and therefore access ... remove Domain Admins from Administrators and have ... > workgroup connection and cannot see the the rest of the ... Get a different ISP that does not dictate what must be ...
    (microsoft.public.windowsxp.security_admin)