Re: Domain Controller Security
- From: "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx>
- Date: Thu, 26 Jan 2006 00:30:13 -0700
Sure, or even just Adminsitrators fits the posters request.
Joe however is correct in providing the precautionary warning, as
either Server Operators or Administrators could without too much
effort elevate themselves to Domain Admins (or Enterprise Admins
if on the forestroot domain).
As such some feel it is better to not pretend that one has gained
something solid by not making use of Domain Admins membership
to begin with (so that all due precautions are attended to).
"Ondrej Sevecek" <ondra at my_surname dot com> wrote in message
news:uaYjjjDHGHA.3752@xxxxxxxxxxxxxxxxxxxxxxx
> Sever Operators.
>
>
> O.
>
>
>
> "Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx> wrote in message
> news:uLCJI8KGGHA.1396@xxxxxxxxxxxxxxxxxxxxxxx
>> You can't do it. They have to have admin rights to the DC and once they
>> have that they have more than enough rights to escalate all the way to
>> enterprise admin or anything else they want.
>>
>> The way this was handled in a fortune 5 company I managed 400 global DCs
>> for (with 3 admins and a manager) was to demote DCs when hardware work
>> needed to be done. If that couldn't occur, the DC was cut out of the
>> forest and reloaded and the admin did the work and then it was
>> repromoted.
>>
>> With Longhorn AD this will be a little easier to handle in WAN Site
>> situations.
>>
>> --
>> Joe Richards Microsoft MVP Windows Server Directory Services
>> www.joeware.net
>>
>>
>> corydch@xxxxxxxxxxx wrote:
>>> I'm running Windows Server 2003 in Active Directory environment. I am
>>> trying to trim my domain administrators but having trouble because I
>>> have people who administer the hardware for a domain controller who I
>>> want to remove from the group. Anyone know of a way to give non-domain
>>> adminis access to device manager for hardware purposes without making
>>> them full domain administrators? Any suggestions would be appreciated.
>>>
>>> Cory
>>>
>
>
.
- Follow-Ups:
- Re: Domain Controller Security
- From: Joe Richards [MVP]
- Re: Domain Controller Security
- References:
- Domain Controller Security
- From: corydch
- Re: Domain Controller Security
- From: Joe Richards [MVP]
- Re: Domain Controller Security
- From: Ondrej Sevecek
- Domain Controller Security
- Prev by Date: Re: Windows Server 2003 Security Guide 2.0
- Next by Date: Re: Windows 2003 security issue
- Previous by thread: Re: Domain Controller Security
- Next by thread: Re: Domain Controller Security
- Index(es):
Relevant Pages
|