Re: Admin with no Rights to Active Directory

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 03/19/05


Date: Sat, 19 Mar 2005 03:49:13 -0500

You can't, anyone who can make changes to services, files, etc on a DC can seize
domain admin access rights and even Enterprise Admin rights. Do not let anyone
but domain admins log into DCs.

   joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
DebraH wrote:
> How do I make someone an admin but take away their rights to making changes 
> within Active Directory? I would like to give a support user the ability to 
> logon to Domain Controllers to troubleshoot DHCP, DNS and some applications 
> that run on the server, but I do not want them to have the ability to make 
> changes to Active Directory (create or delete OUs, delete admins etc). 
> 
> Thanks
> dhodgkins61@comcast.net


Relevant Pages

  • Re: Should I still buy SBS 2003 Premium w/ ISA in light of XP SP2s ICF2?
    ... Admin rights is a very simple story. ... relying upon the firewall to block accordingly the access to workstations, ... don't have the same level of packet-filtering in your favor that ISA ...
    (microsoft.public.windows.server.sbs)
  • Re: Moving DCs From Default OU ?
    ... You cannot protect against this in any way you dream up because it just cannot be done with Active Directory. ... You might as well make them Domain and Enterprise Admins, at least you will be honest with yourself them on what rights they have. ... Again, I don't care who told you otherwise, you cannot protect the AD from someone you give admin level rights or in fact even server operator rights or even less. ... In almost every case it the thought to do this is based on some misunderstanding on how Domain Security works or some stupid plan to have a pretty hierarchy. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Impact of removing administrative rights in an enterprise running XP
    ... While it is true that you can push out patches and software via group ... reporting mechanisms for software/patch installations whatsoever. ... Quite often, the admin rights are ...
    (Focus-Microsoft)
  • Re: Impact of removing administrative rights in an enterprise running XP
    ... the network admin is "Admin" of the network... ... they should only have/need the appropriate rights for their role in the firm. ... reporting mechanisms for software/patch installations whatsoever. ...
    (Focus-Microsoft)
  • Re: Impact of removing administrative rights in an enterprise running XP
    ... You can easily install patches without admin rights... ... WSUS can push out patches and the workstations do not need admin rights. ... Yes, there are success stories, but it's totally dependent on a managed network. ...
    (Focus-Microsoft)