Re: Blocking "Enterprise Admins" permissions

From: Chriss3 [MVP] (noSpamHere_at_chrisse.se)
Date: 07/06/04


Date: Tue, 6 Jul 2004 20:26:59 +0200

You can not* restrict Enterprise Admins Group and should not do so, Its a
protected group. How ever if you not trust the members of the enterprise
admin group remove them and try to find another delegation method. You
should only select member that you trust to be Enterprise Admins.

-- 
Regards
Christoffer Andersson
Microsoft MVP - Directory Services
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"Jim Singh" <jsingh07@hotmail.com> skrev i meddelandet
news:OGatCQ4YEHA.3844@TK2MSFTNGP10.phx.gbl...
> Hi -
> does anyone knows of possible implications of restricting/blocking the
> "Enterprise Admins" security group permissions from child level domain
> besides the DHCP pool auth, child domain creation, ADC etc?
>
> does blocking "EA" group from child domain has any impact on replication ?
> and are there any other serious implications ? i.e. attribute/class
> dependencies etc?
> thanks!
>
>


Relevant Pages

  • Re: How to restrict changes to Domain Admin & Administrator Groups
    ... Groups so existing members cannot add other users to these groups? ... I only want our Enterprise Admins group to have change rights to ... Blocked inheritance with exception of Enterprise Admins ... privs do not get extra privs. ...
    (microsoft.public.security)
  • Re: problem with "Restricted Groups" within a GPO linked to my dom
    ... You are saying that the users no longer appear as members of the RG but the ... logon again if you are using the test user account so that their security ... > groups: Administrators, Backup Operators ... > Domain Admins, Enterprise Admins ...
    (microsoft.public.security)
  • Re: How to block off Enterprise Admin in a different tree but same forest?
    ... I've read about blocking EAs from child domains (in a book by authors whom I ... completely trust) and they didn't mention any repercussions other than the ... >> This can really break the ability to accomplish forest wide maintenance. ... >>> Enterprise Admins you need new Enterprise Admins. ...
    (microsoft.public.win2000.active_directory)
  • Re: Container Administration where you can block out Enterprise Admins
    ... Hi Samuel, Enterprise Admins are a very power full group, Members of this ... by this is don't think the way of restrict members of the Enterprise Admins ... In your case use the Delegate Of Control Wizard to delegate rights to threes ...
    (microsoft.public.win2000.active_directory)
  • Re: Separating domain admins and enterprise admins
    ... it is IMPOSSIBLE to prevent members of administrators, domain admins and enterprise admins doing things you do not want them to do! ... * This posting is provided "AS IS" with no warranties and confers no rights! ...
    (microsoft.public.windows.server.active_directory)

Loading