Re: Domain security privileges and Group Policy



You can make it more difficult for an admin or a DA to
do what they want, have their way with your deployment,
but you cannot stop them if they are determined.
Also, to get to that point of making it difficult, you need
to be pretty good at the settings, certainly better than they.
If they are not usefully restrained then your deployment
is open to the impact of their point and click experiments.

Roger

<j_pickett@xxxxxxxxxx> wrote in message
news:1170153923.428760.263490@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

I have a question which I hope somebody may have an answer to.

I would like to know whether there are any implications of making an
ordinary user a member of Domain Admins on a Windows 2003 domain while
at the same time placing said user into a restricted GPO.
What I would like to find out is whether by having the limitations of
the GP imposed on this user whether that would prevent said user from
being able to take advantage of the fact they're a member of Domain
Admins?

Any feedback on this would be greatly appreciated.

Thanks,
JP.



.



Relevant Pages

  • Re: ForestPrep Issues!
    ... not load exchange 2003 server on a production box as ... >the Domain Admins, Schema Admins, Enterprise Admins ... >a member of the Schema Admin and Enterprise Admins group ... >> I have a domain with a single active directory. ...
    (microsoft.public.exchange.setup)
  • Re: No user accounts that are Enterpise Admins can connect to othe
    ... enterprise admins is not a member of local servers administrators group, ... only the domain admins group is ... Basically it is from one of the child domains connecting to member servers ... /GROUPS on a w2k3 server or use SECTOK from joeware.net) ...
    (microsoft.public.windows.server.active_directory)
  • Re: Adprep /Forestprep Error
    ... member of domain admins, enterprise admins, schema admins. ... > also be a member of the Schema Admins group to make schema changes at all. ... > the same issues with ADPREP. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Problems with assigning permissions
    ... are those users member of any default admin ... then the issue here is the adminsdholder object that protects any ... If the ACL that is on the AdminSDHolder object is ... the inheritence tab and the "admins" are not part of any protected gourp (by ...
    (microsoft.public.windows.server.active_directory)