Re: Restricting "Enterprise Admins" sec group

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 07/03/04


Date: Fri, 02 Jul 2004 21:42:00 -0400

I will make it very simple.

It is impossible with the current design of active directory to effectively
block Enterprise Admins from any part of the forest. There are too many ways
they can get around anything you set up. Do not think about doing it because it
would simply give you a sense of false security.

If you do not trust your Enterprise Admins, fire them or set up your own forest.
That is the only realistic secure options.

   joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
Jim Singh wrote:
> Hi -
> does anyone knows of possible implications of restricting/blocking the
> "Enterprise Admins" security group permissions from child level domain
> besides the DHCP pool auth, child domain creation, ADC etc?
> 
> does blocking "EA" group from child domain has any impact on replication ?
> and are there any other serious implications ? i.e. attribute/class
> dependencies etc?
> thanks!
> 
> 


Relevant Pages

  • Re: New child domain
    ... Error message when you run the Active Directory Installation Wizard: ... When I try to create a new child domain aA. ... I get the request to run Adprep on Schema master and infrastructure ... forest is ready and the domain is ready. ...
    (microsoft.public.windows.server.active_directory)
  • Re: gracefully removing a child domain
    ... The child domain will retain their existing DC's... ... forest and using ADMT to transfer their accounts prior to cut over? ... Then with Exchange, you have to figure out what to do with the mailboxes. ... PPT Presentation - Active Directory Design and Deployment- Tales of the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Installing a DC 2003 on 2000 Forest (ADPrep problems)
    ... Are you using R2 or 64 bit in the child domain? ... The Active Directory Installation Wizard cannot continue because the ... forest is not prepared for installing Windows Server 2003. ... information about using the Adprep, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Child Domain
    ... Did you ran DCPROMO to successfully remove the child domain ... from the forest before you formatted the Domain Controller, ... 230306 - HOW TO: Remove Orphaned Domains from Active Directory: ...
    (microsoft.public.win2000.active_directory)
  • Re: Clarification needed on domain admins scope in child domains
    ... Forest is the only security boundary and the domain is ... Admin of a child domain within the forest can use the SID History attribute ... How ever this is also a question how trusted the domain admins within your ... domain admins group as the role enterprise admins, and need security, deploy ...
    (microsoft.public.win2000.active_directory)