Re: Unauthorized user creating Computer accounts on AD

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: David Adner (davidadner_at_yahoo.com)
Date: 03/06/04


Date: Fri, 05 Mar 2004 20:50:59 -0600

By default, all users can create up to 10 computer objects.

Richard wrote:
>
> Here's the deal: I work as a sysadmin for company where a
> user showed me how he was able to create a computer
> account on AD. Based on what he's told me, he's always
> been able to but he doesn't know why and how and no one
> else has the ability.
>
> He's neither a member of Enterprise Admin, Domain Admin,
> or Account Operators group.
>
> He's creating it where it's going into the default
> Computer Container in the root of the Active Directory and
> his account was not delegated any control.
>
> I checked his group membership and none of the groups he's
> a member of are within the administrative groups named
> above.
>
> I verified that he does not have admin rights in the sense
> that he could not access an administrative share on either
> the network or servers.
>
> What's going on???!!!



Relevant Pages

  • Re: User Rights on Domain but Admin Rights on Computer
    ... Any domain account can be added as a member ... of a particular machine's Administrators group to make that domain ... account an admin on that one machine. ...
    (microsoft.public.windows.server.security)
  • Re: Giving local Admin rights to AD 2003 Domain Admin users
    ... Once I connect the machine to the domain it took the old member name and I used the existing domain account to logged in. ... When I logged on to other machines using the same account I could do admin tasks, But not when I looged in to this machine. ... BUT the part I dont understand is in other machines this account can do admin tasks with out addin the account as a member of local admin. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Administrators are treated as Users for file permissions
    ... I've clicked Deny for all permissions ... > because my admin account was a member of Users (XP by default made it ... So I removed the Member Of Users entry from my admin ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Admin shares
    ... >You may be prompted for a password if the account you ... >on your local machine is not a member of the local admin ... >(and you use that account to open your session). ... username/password as a member of that group... ...
    (microsoft.public.win2000.security)
  • Re: XP client - Admin Rights
    ... and also that you have no way to map the admin shares. ... options find the policy to rename Administrator and rename it to this ... same - using an account name of your choice. ... make sure that Domain Admins is a member of the local Administrators. ...
    (microsoft.public.windows.group_policy)