Re: ActiveDirctory security questions

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Don't even think about changing the context of the services that come with Windows, you will just break it.

As for DA/EA/Administrators. When you get down to it, each can escalate to the others if they don't have those rights already. If DAs are not in the administators group of the DCs you will find things that don't work exactly as expected.

I really don't understand what you think you are going to accomplish by trying to lock down the admin groups and localsystem. Windows isn't designed to have you try and lock down those items and when you get down to it, you can't.




-- Joe Richards Microsoft MVP Windows Server Directory Services www.joeware.net


mschunk@xxxxxxxxxxxx wrote:
Thank you VERY much for your comprehensive reply....getting my head
straight.

On DA's and EA's...I have but one domain in the forest, and I think
you just taught me something new.

So, when a workstation/server is joined to a domain...DA is added to
that PC's LOCAL Admins group by default.  I've seen that. OK.  EA's
however, are not.

I assert then, that EA is a forest thing, DA is domain thing...and the
EA's, by default, become members of the DA of each domain that is added
to the forest...that DA's are, by default, added to the LocalAdmins of
each comp that is joined...but that DA's do NOT _have_ to be members of
the _domain's_ built-in administrators group.  It's Just that way by
default, like it is for newly joined PC's.

Am I getting warmer???

On SYSTEM.  So they _ARE_ the same thing.  ("LocalSystem" in services
snapin = "System" in ACL security windows.)

Well, let me count the number of services.  Oh my.  There are a TON, as
you know I'm sure.  So, how feasible is it to run most services within
a context other than localsystem?

event Log
Clip Book
Alerter
COM+ event system
Computer browser

...I don't want to list them all here...

What about "big" ones like:

Disk Manager
Workstation (lanman)
Sever (lanman)

...Telnet?

WMI services?

...Security Accounts Manager?

Geez.  as I write I'm staring at the services list, and even w/ years
of working with windows, I don't even know what half this stuff REALLY
does.

What about drivers?  I got an ATI card installed on the DC and it runs
something I know little about: the "ATI Smart" and "ATI HotKeyPoller"
services?  Change account, bounce service and pray?

What about DNS and DHCP.  As long as these two run in a context that
has access to their data files...will they run?

Or am I wasting time?  It just seams like LocalSystem is an awefully
big hole.

...But, LocalSystem has power over only it's domain? or does it get FC
of all child domains as well?

.



Relevant Pages

  • Re: First thoughts on Lion
    ... Though, to be fair, that is largely what Windows 7 was about, too. ... the context of the dock and the finder is different. ... the completely arbitrary Save / Open dialogs used in Windows. ...
    (comp.sys.mac.advocacy)
  • Re: First thoughts on Lion
    ... Apple did fine. ... I knew they rewrote the Finder in Cocoa, ... the context of the dock and the finder is different. ... the orb with the Windows logo. ...
    (comp.sys.mac.advocacy)
  • Re: listing to a file
    ... batch file but I cannot remember where I found it. ... To create the entry in the context menu it's necessary to first create a ... Save the file in your WINDOWS folder as shown in, ... File Listing will probably be most useful, but you can name yours something ...
    (microsoft.public.windowsxp.general)
  • Win Explorer Context Menu Queue it up, Add to Playlist NOT WORK
    ... During all this year by now I noticed one big problem with Windows ... Windows Explorer Right click Context menu on multimedia files (e.g. .mp3, ... In the first, I was thinking that maybe some WMP Plug-in, or Visualizations ... start to install more Software on it. ...
    (microsoft.public.windowsmedia.player)
  • Re: Right Click Crashes Windows Explorer
    ... Wondering why troubleshooting using ShellExView did not isolate the ... Apparently by doing this I insured that PowerDesk's Context Menus load ... What about other shell extensions (not only Context Menu handlers). ... see if the Event Viewer provides any clue on the Windows ...
    (microsoft.public.windows.vista.installation_setup)