Re: What is the best way to restrict access to Domain Admins on certain folders?



Ravi <ravichandra.thalluri@xxxxxxxxx> wrote:
Some of the folders in our file system contain sensitive financial
data. The file server is managed by our IT department. How do I
restrict the people in Domain Admins group (some of them are from IT
Department) from accessing sensitive data? If I remove read
permissions to Domain Admins, backup jobs may fail.

EFS. But be very careful. Your domain admins/IT staff are the ones you need
to rely on to administer/manage/back up and restore your data. If you
encrypt something and they can't work on it/back it up, and you can't
unencrypt it, your data is lost. Hire only admins you can trust, and have
everyone sign computer use agreements, nondisclosure agreements, and so
forth..

Note for future This isn't really the best group for a question like this -
I'd post in microsoft.public.windows.server.active_directory with a possible
crosspost to microsoft.public.security.


.



Relevant Pages

  • Re: NT4->2003 Computer Account Migration Problem
    ... win2k3 domain, domain admin is by default the computer's local admin. ... and remigrate the computers using a specific account to perform migration ... Add NT Domain Admin to Win2k3Dom Domain admins group and Win2k3Dom ...
    (microsoft.public.windows.server.migration)
  • Re: Domain user with local administrators right
    ... domain account to the domain admins group, this is in turn a member of the ... with this domain account (selecting the domain from the drop down box under ... If the server is a domain controller, then there is no local administrators ... group so membership of domain admins should suffice. ...
    (microsoft.public.windows.server.active_directory)
  • Exchange 2007 forest prep
    ... The services refuse to start unless the Exchange Server security group ... is part of the Domain Admins group. ...
    (microsoft.public.exchange.admin)
  • Re: Domain admins
    ... When I started to do work for them, the network was already in place. ... tried to remove tehm from the domain admins and leave them just as domain ... > member of the Domain Admins group so that all users can install ...
    (microsoft.public.exchange.admin)
  • Re: Should be a simple task
    ... Go to the domain admins group and try to add a global or universal group to it. ... Phil ... > 2000 Server. ...
    (microsoft.public.windows.server.active_directory)