Re: Active Directory Permissions



Don't randomly just hand over the keys to the LAN (Making them the same as
you) because in the end you will be held responsible for problems and will
probably have to fix any errors.

Learn what they need to do, change passwords, enable accounts, create users,
etc... and provide them the least amount of privelge from the definition of
their job.

Once this has been defined Delegate Control to a security group and then
make users a member of this group, this way as people come and go all you
have to do is change membership of the group..

--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

"Wirelondon" <Wirelondon@xxxxxxxxx> wrote in message
news:1155015181.887393.214010@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I have been asked by manager to setup access for the Helpdesk Team to
access the Active Directory.

I need some advice, as I asked what access should I give the Helpdesk
team he replied "give them same access as you" But I don't want
them having full control.

Our helpdesk team is 3 people who look after all 1st line & 2nd line
support issues.

Has anyone else been asked to grant people access, but not wanting to
give them full control?


Many thanks

Phil



.



Relevant Pages

  • Re: sucking rumpled notes into Pick
    ... control to take in REAL rumpled notes! ... any TWAIN-compliant scanner. ... You need to look at a better brand of OCR s/w! ... What is this "diminishing LAN quality" of which you speak? ...
    (comp.databases.pick)
  • Re: Hacked and remote controlled computer
    ... look for strange connections with netstat... ... > remote control aplication, which I couldn't found. ... on your LAN that blocks all potentially dangerous ports? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Intruders....?
    ... > If you can't control the building in this way, then quite frankly, you ... > get on the network physically, they still can't access the Internet. ... > this won't protect your LAN itself. ... Apparently the idea was to incorporate this technology in 2003 R2 but the ...
    (microsoft.public.windows.server.networking)
  • LAN Help needed
    ... its' been a long road but I finally have a LAN working at home. ... internal machine into the address bar of konqueror and I get ... I would try out the article by Marcel Gagne about remote desktop control. ...
    (alt.os.linux.suse)
  • Re: Active Directory Permissons
    ... someone here who is able to edit everyones peoples contact details in AD, ... full control, i dont want them to be able to change passwords, move people, ...
    (microsoft.public.windows.server.active_directory)