Re: Domain Admins Group -- Trying to trim membership



"Tom Glasser" <TomGlasser@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7E31AF20-C60D-49F6-ABE6-F910B0A6E584@xxxxxxxxxxxxxxxx
I am being requested to analyze the current 15 - 20 members of the
Domain Admins group with the goal of reducing membership in this
group to an absolute minimum. But it seems at first blush that mem-
bership in this group is necessary to maintain various functionalities.

Is this a common problem in the Windows Server world? Anyone have
similar experiences to share or any advice on attacking this issue?


IMO it is an all too common problem in the world of the administration
of Windows Server. It is not inherent in Windows Server nor AD, but
in the ineffective use of the available capabilities.

Have each justify as to what the account is used for that requires
Domain Admin. Then, you will likely find 90% of that can be
accomplished with account that are not admin but have delegations,
and/or membership in custom groups that are used to receive other
grants (admin on client machine). If you really want to drive the
point home, then have each outline what else is done with the
account (beyond what they said as justification for its being a
Domain Admin) and then show the risks from those uses of the
accounts


.



Relevant Pages

  • Re: Finding a Hacker
    ... definitely had the capability to obtain the domain admin credentials and may ... If the hacker did get in remotely using an administrator account on the ... Your problem is not restricting remote desktop connections. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need to filter domain admin from GPO
    ... But think always about the part that a deny is the highest blocking you set and if you forget that you have set a deny or you are not in and someone else have to search for errors, it will be really heavy to find it. ... It's best practice to use a 2nd administrator account as your ... Block inheritance (I would have to move the domain admin from ... particular GPO using ACL deny. ...
    (microsoft.public.windows.group_policy)
  • Re: Administrator--Client installation account problem
    ... I stated the account was only required to be a ... Of course if it is a domain admin that works also. ... Jeff said to use a Regular domain user, ... You do not have to be in advanced security to push the client. ...
    (microsoft.public.sms.admin)
  • Re: Need to filter domain admin from GPO
    ... Normally Block inheritance works fine. ... What GPO setting do you like to filter? ... It's best practice to use a 2nd administrator account as your regular ... Block inheritance (I would have to move the domain admin from ...
    (microsoft.public.windows.group_policy)
  • Re: SQL account rights
    ... Please advice what is the best, suitable rights rather than domain admin ... Warren Brunk - MCITP - SQL 2005, ... Add it as a login to the SQL Server ... files, or backups, make sure that the service account has Full ...
    (microsoft.public.sqlserver.security)