Re: Need help locking down a server



Hi Chris,

Only IT staff that needs to administer domain controllers (physically) needs
to be member of Domain Administrators group. For everyone else it is enough
to be Administrator on the systems that they need to manage (e.g. Exchange
server). You can even limit this and delegate some other tasks (e.g. Backup
Administrators,...).

If your question is how to limit Domain Administrators from logging onto
Exchange server -- you can't. You simply can't limit someone who is Domain
Administrator. Even if you deny someone logon locally permissions, if the
person is Domain Administrator -- he/she can change that policy at any time
and allow themselves to logon to any server...

--
Mike
Microsoft MVP - Windows Security

"Chris Hall" <someone@xxxxxxxxxxxxx> wrote in message
news:e7gSEe5HHHA.3952@xxxxxxxxxxxxxxxxxxxxxxx
Greetings,

I'm looking into options to secure our mail server (Exchange 2003 on
Windows
2003). We have an IT staff of 5 people, which includes our dept mgr, all
of
which have access to the administrator password and whose accounts are
members of the Domain Admins group. What I propose to do is:

1. Change Admin password, allowing only one person access.
2. Disable Remote Desktop
3. Deny Logon Locally.

The only thing I can't seem to figure out is how to deny all users except
administrator.

If anyone has any suggestions, I'd appreciate it!




.



Relevant Pages

  • Re: How to block users from installing other apps
    ... On Thu, Jul 03, 2003, Jane Han wrote: ... Explain the risk of damage caused by unauthorized programs. ... Consider how much easier it is to exploit local administrator ... accounts to become domain administrators. ...
    (Focus-Microsoft)
  • Re: Block domain administrators in windows sharepoint services
    ... Standard is that the *WSS server* Administrator has access to WSS ... Make sure that domain administrators are not included in the Administrator ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Server Container disappears - Please help I am stranded
    ... However, I did find DENYs for Administrator, Exchange Administrator and ... Domain Administrators if I used the Distinguished Name of my actual ... server and not just the servers group. ...
    (microsoft.public.exchange.admin)
  • Re: Windows Service - Event Log
    ... I didn't say the Administrator account. ... Administrators group on the local machine." ... I didn't advocate using a member of the Administrator's group; ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: User rights and XPe Component Database
    ... - On a PC, I installed the tools and SP2 update, database etc.. ... - I create a new local user on this machine, I called it XPeUser ... I add XpeUser as a member of the Administrators ... Of course he souldn't be administrator. ...
    (microsoft.public.windowsxp.embedded)