Re: Domain Users with 2003 adminpak can see AD!

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/12/04


Date: Thu, 11 Mar 2004 23:47:44 GMT

As Paul said, this is SOP. A domain user can go to My Network Places and browse or
search Active Directory. All AD objects have permissions to them somewhat like ntfs
folders do. You can remove everyone/users from an object [and replace with authorized
groups] and they will not be able to see it and this may be desirable for shares,
printers, or even an OU as long as the user does not exist in that container nor need
to access objects in that container via AD. However if you try that be very careful
as I believe a user needs read permissions to at least the domain controller
container, the domain container, any OU that they may be in, and their user account
or they will not be able to change their password and Group Policy user configuration
will not apply to them. --- Steve

"klose" <norepl@noreply.com> wrote in message
news:%23vCsYW6BEHA.2768@tk2msftngp13.phx.gbl...
> If a regular domain user, installs the 2003 adminpak, they can browse the
> ADUC containers.
>
> a) Why is this not locked down to at least a domain administrator or some
> other group?
>
> I am aware of the GP that can lock down the various tools, and the
> customization of the mmc window, but can not control it from the default
> tool within the administrator tools console.
>
> b) After you grant use of the ADUC tool to certain members, they can see
> EVERYTHING.
> The default permissions on the ADUC objects allows Authenticated Users at
> least RO rights on the Builtin, computers, ForeignSecurity Principles...etc
> folders.
> Can these rights be changed without affecting other system/domain needs?
>
>
> My goal is to deploy minimal tools to remote office administrators, I have
> already used asdi edit and delegation wizard to effect limitations....but
> they still see way to much.
>
>



Relevant Pages

  • Re: Exchange 5.5 - Restored data
    ... exchange server (using Exchange Administrator) I am ... You do not have the permissions required to complete the ... >sub-recipients container called '5.5 Contacts' you will ...
    (microsoft.public.exchange.misc)
  • Re: EMERGENCY: Files lost
    ... Windows XP Home Edition, with SP2. ... or other folders and files at that level. ... Administrator, I do have normal access to all files and folders. ... You now need to edit the permissions of every file (step 6 on my page. ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: Do not have accessibility to change certain file names
    ... ownership and permissions supersede administrator rights. ... you can set XP Home permissions in Safe Mode. ... Open Explorer, go to Tools and Folder Options, on the view tab, scroll to ...
    (microsoft.public.windowsxp.accessibility)
  • RE: Administrator without full pemission?
    ... Checked the permissions on Failed Mail folder: ... Checked Active Directory Users and Computers, Administrators, Members Tab. ... please contact your administrator'. ... how do I get the mails in Failed Mail Folder ...
    (microsoft.public.windows.server.sbs)
  • Re: Access Denied: backed-up Documents and SettingsUser
    ... ownership and permissions supersede administrator rights. ... you can set XP Home permissions in Safe Mode. ... Open Explorer, go to Tools and Folder Options, on the view tab, scroll to ...
    (microsoft.public.windowsxp.accessibility)