Re: domain admin account impersontating



good morning

thank you for the information.
so, can we say that is " by design " ?? it happens because it does. ( not
flaming, just trying to make things clear )
does this happens only on admin accounts ? can i create an user on the off
domain pc and logo to the shares with the user's domain password ?? this
kind of breaks the concept of windows domains doesn't it ??

apart from the obvious of having the domain admin account " on the loose ",
are thre any other security issues that i should be on the lookout for ??
and before someone says it, i fully agree that having the local admin user
equal to the domain admin is a cumbersome error. a malpractice that i must
correct.

thank you
PLeite
-------------------------------------------------------------------
"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> escreveu na mensagem
news:%23cqF1faAHHA.4592@xxxxxxxxxxxxxxxxxxxxxxx
Windows has done this for a very long time.
If you have two accounts, in separate authentication realms, and those
accounts have the same name and password, then while using one of
them it is possible to access resources in the other realm by means of
the other account. This happens "transparently" with a login behind
the scenes when an access attempt is made. It is not a matter of the
accounts having the same SID (which they do not) but that one can
log in as the other by presenting its own credentials since they match.


"Pedro Leite" <aa> wrote in message
news:%23eBIMYaAHHA.4592@xxxxxxxxxxxxxxxxxxxxxxx
good afternoon

can anyone explain this behaviour ?? as described
setup is sbs 2k3

recently added a new pc to the network and to the domain for updates and
application deployment.
so, i named the pc admin account the same as the domain admin account
and
gave it the same password.
now, the new pc is off the domain but the admin account is still the
same
with the same domain admin password.

whenever i log to the pc with the admin account, i have full control
over
the domain machines, c$ share, all users document folders, all shares,
direct internet acces through the firewall...

questions, is the domain admin sid the same as a local admin sid's
account
?? the authentication being made with a blend of username and password,
all
mixed up, hashed whatever and then sent to validation ??

isn't the domain admin account user equal to domainname\admin and the
local
admin, machinename\admin ??

for my knowledge please comment on the above

thank you

Pedro Leite

--------------------------------------------------------------------------
--
---






.



Relevant Pages

  • Re: Groups
    ... It is a bad idea to add normal users to the admin account, ... legitimate reasons to add certain users to the local admin accounts. ... Power Users can install most - but not all - software. ... Free Computer Help - http://forums.techarena.in ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions
    ... The local admin account and password are in sync. ... Joe Richards Microsoft MVP Windows Server Directory Services ... full control share permissions but limited NTFS permissions propagated ...
    (microsoft.public.windows.server.security)
  • Re: Best Practice for Domain & Local Admins
    ... are you referring to the Security one within Event Viewer that can be included in mailed reports? ... 3)I'm guessing the answer is yes, but should the pass phrase philosophy be set for BOTH domain AND local admin accounts? ... Make that admin account a passphrase. ... Any administrative tasks that need to be accomplished on local machines would use the local admin account. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 Premium, user changes password and loses network share access
    ... If no local admin account, log on as a domain admin. ... profile that has local admin permissions on the workstation. ... Merv Porter [SBS-MVP] ...
    (microsoft.public.windows.server.sbs)
  • Re: Install program at startup
    ... Will the HKLM\RunOnce run as a local admin? ... When I logged in with an admin account, ... prefixed with an exclamation point to defer deletion of the value until ... command line is run unless overridden as noted above. ...
    (microsoft.public.windowsxp.general)