Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RE: Restrict the Domain Admin

Subject: RE: Restrict the Domain Admin
Date: Mon, 19 Sep 2005 11:13:28 -0700
Hi List,
Is there a way to restrict access of a Domain Admin?

Example, can we allow a Dommain admin to do everything EXCEPT user
management (e.g. password reset)? 

We want to secure our environment, and do not want to have "ALL-POWERFULL"
domain admins around

Thanks for your suggestions

P.S. Environment: Windows (2000 & 2003) - Active Directory

I would not recommend messing with the Domain Admin rights.  You might end
up shooting yourself in the foot.

Instead you could consider creating new domain groups with just the rights
that you want them to have and restrict the Domain Admin group to just a
small number of user accounts or maybe even just one for emergencies.

There are three ways to control the power and rights of your own group:

1. Control the groups that your new group is a member of.
2. Manually change the user rights that you assign to the group
3. Use Active Directory to delegate control of objects in an OU to your new
group.


<Prev in Thread] Current Thread [Next in Thread>