Re: Security best practice help!!! local admin addition!

From: Philip Nunn (bigphil_at_newsgroups.nospam)
Date: 01/07/05


Date: Thu, 6 Jan 2005 16:36:15 -0800

Thanks for all the good input guys! I will print this out and let them read
what the real pro's thought about this idea!

Thanks,

Phil

"Chris Weber [Security MVP]" <chris@dev.nul> wrote in message
news:%23$2ocpv8EHA.1524@TK2MSFTNGP09.phx.gbl...
> That's like being taking a group of 20 children to the amusement park,
> then letting them run loose and hoping they come back. Not very
> responsible. It's often done in development environments, but believe me
> there are better practical ways. Giving everyone admin rights can wreak
> havok on network security.
>
> My personal favorite is how local administrators can see in plain c l e a
> r t e x t all of the service account passwords on the machine.
>
> Consider the following scenario which I have personally taken advantage of
> 100 times at various client networks, and extremely large ones.
> 1. Domain administrators need to run backup software across the network
> 2. Backup software needs to install a backup agent "service" on every
> workstation
> 3. This service runs as a Domain Admin account
> 4. Where is that Domain Admin password stored now? If you guessed in the
> "protected" Registry of every workstation, you're right! Furthermore, any
> administrator of any workstation can easily access that password in plain
> clear text.
>
> There, now everyone's a Domain Admin - is that productivity?
>
> /Chris
>
>
>
> "Philip Nunn" <bigphil@newsgroups.nospam> wrote in message
> news:eVmeUhc8EHA.3476@TK2MSFTNGP15.phx.gbl...
>> Hello everyone,
>>
>> I would like everyones opinion on a subject of extreme importance to me.
>> Right now my companies computers are setup so that all users are ONLY
>> members of the local users group to enforce security accross the network,
>> reduce support costs and is an overal good practice to follow. This is
>> all about to change for me. We are in the process of consolodating
>> domain and with this my IT managers want to add everyone to make them
>> members of the local administrators group!!! I strongly disagree with
>> this and did not make this recommendation. I am trying to prevent this
>> from happening to my network as I dont think this is in the best interest
>> for the network/company. Please give me your opinions on this and what
>> your companies do. Any links to articles with reasons why this is not a
>> good idea would be greatly appreciated and MVP/MSFT person's opinions
>> would be great!
>>
>> Phil
>>
>
>



Relevant Pages

  • Re: Security best practice help!!! local admin addition!
    ... My personal favorite is how local administrators can see in plain c l e a r ... Domain administrators need to run backup software across the network ... Where is that Domain Admin password stored now? ... Please give me your opinions on this and what your ...
    (microsoft.public.windowsxp.security_admin)
  • RE: User able to create folders on network drive he had no permission
    ... setup for him on the network was able to create files and folders on ... a network drive he should only have had read access to. ... The PC was setup using a domain admin account (I know, ... to assign permissions to specific groups. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: User able to create folders on network drive he had no permission
    ... setup for him on the network was able to create files and folders on ... a network drive he should only have had read access to. ... The PC was setup using a domain admin account (I know, ... difference with the *user* permissions on the network. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Direct Access to SBS from Client Computer
    ... Does the user have domain admin or local admin permissions? ... Merv Porter [SBS-MWP] ... Change button) to join the network again. ... What's the best way to setup the client computer to be able to ...
    (microsoft.public.windows.server.sbs)
  • Re: Need limited domain admin rights user account.
    ... Are you saying there to create a custom group that would be added ... or how to give most of the permissions that a Domain Admin would have. ... > the machine local Administrators group would likely also be. ...
    (microsoft.public.windows.server.security)