Re: Deny rights question

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/10/05


Date: Mon, 10 Jan 2005 13:04:50 -0600

There are some folders that they will be able to open by default on a domain
controller such as sysvol. They would be able to open and list any share
that has share and ntfs permissions for everyone/users/authenticated users
or other groups that they are members of. If these folders are restricted to
"administrators" for permissions then you want to be sure to double check
membership in the domain admins, enterprise admins [if available] and
administrators groups in Active Directory Users and Computers. If they can
access the default hidden admin share on a domain controller such as C$, you
know they have excessive permissions in the domain. --- Steve

"Jeff Cichocki" <jeffc@belgioioso.com> wrote in message
news:unxM%23hy9EHA.3236@TK2MSFTNGP15.phx.gbl...
>I have a new 2003 environment that is managing some XP machines. A few of
>the XP machines have users that set up as local admins to their respective
>machines. Is there a way to prevent their local admin rights from giving
>them admin rights to the domain servers? Specifically, they can browse the
>network and open any folder on the server because of this scenario.
>
> Thanks
>
> Jeff
>



Relevant Pages

  • Re: Deny rights question
    ... There are some folders that they will be able to open by default on a domain ... membership in the domain admins, ... access the default hidden admin share on a domain controller such as C$, ... >I have a new 2003 environment that is managing some XP machines. ...
    (microsoft.public.windows.server.general)
  • Re: Add another domain user group to local administrators of all computers in an OU with removing ot
    ... If you have a group "mylocaladmins", which is added to restricted groups, ... if you have a lot of local admins you can have a lot of more problems. ... Select add on the Members of this group and then add the members ... machines you may not want it applied to. ...
    (microsoft.public.windows.server.active_directory)
  • Re: local policy
    ... Ace Fekay [Microsoft Certified Trainer] wrote: ... for him to go home for the day, remove him from domain admins, and/or local admins, apply restricted groups, so you have full control of the machine and he can no longer make changes. ... It actually doesn't ease the management pain on the machines, it sometimes makes it harder to push a common config or enforce a valid configuration throughout all clients. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Easiest way of removing access permissions from folders?
    ... understand you plan to remove 'OldDomain\Domain Admins' permission on the ... 'OldDomain\Domain Admins' privilege from these folders? ... My opinion is to use subinacl command; however, you need to develop a batch ...
    (microsoft.public.windows.server.migration)
  • Re: Add additional domain group to local admins groups?
    ... Howdy Valkan! ... workstations and also have the right to add and remove machines names to the domain, but not be domain admins. ... If it's only about granting the rights for adding machines and accounts to active directory, you could just right-click the OU and choose "Delegate Control". ...
    (microsoft.public.windows.group_policy)

Loading