Re: School Design for AD
- From: "Herb Martin" <news@xxxxxxxxxxxxxx>
- Date: Fri, 20 Apr 2007 17:49:26 -0500
<phil2627@xxxxxxxxx> wrote in message
news:1177097376.113262.250010@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
On Apr 20, 2:23 pm, "Herb Martin" <n...@xxxxxxxxxxxxxx> wrote:
<phil2...@xxxxxxxxx> wrote in messageThanks for the quick reply. We are just worried about:
- locking down the admin accounts
What does this mean (to you) precisely? You are always going to
have SOME admin account in every domain and these will be subject
to the same attacks no matter where they are located IF the network
is accessible.
- students being able to browse DCs (guessing we can "deny" the
student OU on "admin" DCs)
"Browse" means to see in Network Neighborhood and can be turned
off even though it offers very low security exposure (merely know the
share points or servers are there.)
ACCESS to those resources is controlled by PERMISSIONS.
You control permission by GROUPS not OUs though.
- have students login to student computers only (we'd also like to
Generally you WANT them to logon to the domain when they logon
to the computers -- you get easier CONTROL of them this way.
prevent the "log on to" box on the login screen)
You cannot but there are only limited choices for a machine:
1) The machine
2) The Domain of the machine
3) The Domains trusted by the machines domain
And since every domain in a forest effectively trusts every other domain
in that forest this means that multiple domains don't provide full security
boundaries -- if they are in the same forest.
- different password policies for students vs staff (more strict for
staff)
You cannot do this with the built in features in a single DOMAIN.
Password polices are PER domain for domain accounts.
My advice is to make the password policies strict for everyone and
just teach students to deal with it. They will likely have less trouble
than the teachers who must be TRAINED to use good password
security -- if you make passwords strong and don't train them they
will just write them on the side of the monitor or some such place.
--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)
.
- Follow-Ups:
- Re: School Design for AD
- From: Richard Mueller [MVP]
- Re: School Design for AD
- References:
- School Design for AD
- From: phil2627
- Re: School Design for AD
- From: Herb Martin
- Re: School Design for AD
- From: phil2627
- School Design for AD
- Prev by Date: Re: School Design for AD
- Next by Date: Re: Remove Domain Controller
- Previous by thread: Re: School Design for AD
- Next by thread: Re: School Design for AD
- Index(es):
Relevant Pages
|