Re: W2k3 - Recover from lost Domain Admin passwords

From: Ulf B. Simon-Weidner (nospam2-ulf_at_usw-consulting.com)
Date: 01/25/04


Date: Sun, 25 Jan 2004 00:33:43 +0100

Robert Strom says...
[he wants to reset the domain-admin pwd without knowing it]
> The "LOCAL SERVICE" account doesn't have the necessary permissions to use
> the described techniques to change the Domain Admins password (I used the
> default Administrator account in my testing).
>
> I'm all for security, but this seems like a potential nightmare. Physical
> security is really the issue at hand here. All Unix system can be broken
> into with a bootable system CD-ROM. I personally see a need for having the
> ability to recover from a situation where all passwords are compromised
> without having to resort to restoring the entire AD from backup.
>
Hello Robert,

your passwords are more easily compromised if you leave this whole open.

If you are all for security, then I'd create a domain admin password which is
totally random, and something like 30-50 letters. Print it out, and put it into
a safe. Don't use the domain admin account, but create admin accounts which are
individual per user. Give them just the rights they need. Educate them not to
log on with their adminaccount, but their useraccount and use RunAs for
administrative Tasks. Change the domain admin account quite frequently - like
once a month (every other month should be OK as well, if you use about 50
letters). Treat the service accounts like your domain admin account.

Gruesse - Sincerely,

Ulf B. Simon-Weidner



Relevant Pages

  • Re: Mailbox Permissions - Deny Access
    ... why does your domain admin account have a mailbox at all (making the ... This goes against our security ...
    (microsoft.public.exchange.admin)
  • Re: LDAP Authentication from Linux
    ... using an LDAP browsing tool and that account, I can browse the whole AD, but I'm hoping that removing the user from Domain Users stops it from doing anything other than LDAP lookups. ... Depending on the security policy set up, you may require the query to be done securely though. ... and if I bind using a Domain Admin account then all is well and I can login. ...
    (microsoft.public.windows.server.sbs)
  • Re: Are Domains True Security Boundaries?
    ... The ONLY true bondary of security is the Forest. ... So if you do not trust a group of "domain admin" who for whatever reason you ... > We feel that adding a second domain and giving untrusted domain admin ...
    (microsoft.public.windows.server.active_directory)
  • Read only Admin privileges for Active Directory environment?
    ... Our InfoSec team has requested Domain Admin privileges ... on the corporate Active Directory to audit the environment's security. ...
    (Security-Basics)
  • Re: Admin Acct
    ... > We have an obligation in security documentation to discuss the least ... > SMS without Domain Admin rights. ... >> wants to use advanced security, local admin rights and no domain admin ...
    (microsoft.public.sms.admin)