Re: Domain Controller Security
- From: "Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx>
- Date: Fri, 27 Jan 2006 22:29:14 -0500
Actually put me as a servop in a child domain and I will make myself enterprise admin in not to long a period of time.
-- Joe Richards Microsoft MVP Windows Server Directory Services www.joeware.net
---O'Reilly Active Directory Third Edition now available---
http://www.joeware.net/win/ad3e.htm
Roger Abell [MVP] wrote:
Sure, or even just Adminsitrators fits the posters request.
Joe however is correct in providing the precautionary warning, as either Server Operators or Administrators could without too much effort elevate themselves to Domain Admins (or Enterprise Admins if on the forestroot domain).
As such some feel it is better to not pretend that one has gained something solid by not making use of Domain Admins membership to begin with (so that all due precautions are attended to).
"Ondrej Sevecek" <ondra at my_surname dot com> wrote in message news:uaYjjjDHGHA.3752@xxxxxxxxxxxxxxxxxxxxxxxSever Operators.
O.
"Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx> wrote in message news:uLCJI8KGGHA.1396@xxxxxxxxxxxxxxxxxxxxxxxYou can't do it. They have to have admin rights to the DC and once they have that they have more than enough rights to escalate all the way to enterprise admin or anything else they want.
The way this was handled in a fortune 5 company I managed 400 global DCs for (with 3 admins and a manager) was to demote DCs when hardware work needed to be done. If that couldn't occur, the DC was cut out of the forest and reloaded and the admin did the work and then it was repromoted.
With Longhorn AD this will be a little easier to handle in WAN Site situations.
-- Joe Richards Microsoft MVP Windows Server Directory Services www.joeware.net
corydch@xxxxxxxxxxx wrote:I'm running Windows Server 2003 in Active Directory environment. I am trying to trim my domain administrators but having trouble because I have people who administer the hardware for a domain controller who I want to remove from the group. Anyone know of a way to give non-domain adminis access to device manager for hardware purposes without making them full domain administrators? Any suggestions would be appreciated.
Cory
.
- References:
- Domain Controller Security
- From: corydch
- Re: Domain Controller Security
- From: Joe Richards [MVP]
- Re: Domain Controller Security
- From: Ondrej Sevecek
- Re: Domain Controller Security
- From: Roger Abell [MVP]
- Domain Controller Security
- Prev by Date: Re: What is the difference between logging into an AD Domain versus connecting to network resource?
- Next by Date: Re: Windows 2003 security issue
- Previous by thread: Re: Domain Controller Security
- Next by thread: Re: Firewall Profiles
- Index(es):
Relevant Pages
|
|