Restricting Domain Admins

From: Lee (lee_at_nowehere.com)
Date: 06/01/05


Date: Wed, 1 Jun 2005 17:32:42 +0100

Hi,

I would like to stop domain admins from being able to modify the membership
of the domain admins group.

I have modified the following security on thr domain admins group

Removed Write permission
Removed Modify permission
Removed modify owner permission

I have modified the following security on builtin\administrators group

Removed Write permission
Removed Modify permission
Removed modify owner permission

This appears to work fine.

However, after an hour or so, all the permissions that I have removed seem
to reappear, I am pretty sure no other domain admin is adding them back.

Any ideas ?

Thanks

Lee



Relevant Pages

  • Re: Restricting Domain Admins
    ... > Change the security on the adminSDHolder container so that domain admins ... > Modify Permissions ... >>> Removed Modify permission ... >>> Removed modify owner permission ...
    (microsoft.public.windows.server.security)
  • Re: Restricting Domain Admins
    ... > Change the security on the adminSDHolder container so that domain admins ... > Modify Permissions ... >>> Removed Modify permission ... >>> Removed modify owner permission ...
    (microsoft.public.windows.server.security)
  • Re: Restricting Domain Admins
    ... Modify Permissions ... the settings I have changed stop domain admins from ... >> Removed Modify permission ... >> Removed modify owner permission ...
    (microsoft.public.windows.server.security)
  • Re: Restricting Domain Admins
    ... > protect the domain admins group to the level that I require. ... >>> Modify Permissions ... >>> modifying the domain admins group membership, ... >>>>> Removed Modify permission ...
    (microsoft.public.windows.server.security)
  • Re: Restricting Domain Admins
    ... Microsoft MVP (Windows Security) ... > I would like to stop domain admins from being able to modify the ... > Removed Modify permission ... > Removed modify owner permission ...
    (microsoft.public.windows.server.security)