Re: Track Domain Admin.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Sundaram Narayanan[MSFT] (sunnar_at_online.microsoft.com)
Date: 01/28/05


Date: Fri, 28 Jan 2005 10:46:29 -0800

The reality is there is no way to fully audit a domain administrator in a
domain if you don't trust them. The best way to fix this kind of an issue is
not to make anybody a domain admin who is not already trustworthy. If users
want to protect information from domain admins the only way is to use EFS
but even there you need plan your policy carefully.

-- 
This posting is provided "AS IS" with no warranties, and confers no rights. 
Use of included script samples are subjected to the terms specified at 
http://www.microsoft.com/info/cpyright.htm.
"Monica" <Monica@discussions.microsoft.com> wrote in message 
news:1AFB39D6-4413-4833-AC59-53AA480994A3@microsoft.com...
> The domain admins can go into any machines  to see the data either by 
> normal
> logon or share drive (c$, D$). We are asked to provide a accessing log for
> this. Where can I find a accessing log for this kind of access, especially
> for the later one?
> Thank you! 


Relevant Pages

  • Re: Domain Admin Access across Trusted domains
    ... > users to a Domain Local security group, I can't add that Domain Local ... Much, not all, can be conferred my making members of the ... same as making them members of Domain Admins. ... >>> The trust is a two way external trust. ...
    (microsoft.public.win2000.security)
  • Re: Domain Admin Access across Trusted domains
    ... users to a Domain Local security group, I can't add that Domain Local ... security group to the Domain Global group "Domain Admins" ... ... > not attempting to next externals into your globals. ... >> The trust is a two way external trust. ...
    (microsoft.public.win2000.security)
  • RE: software to control domain administrators
    ... "Does anyone know any software to control, audit, or restrict access or privileges to domain administrators." ... I will restate my mantra differently, If you can not trust someone to be in a position of complete un-adulterated control of your network, then they should not be in that position. ... >(assuming we are talking about NT/AD Domain Admins) ...
    (Security-Basics)
  • Re: ADMT v3 Access is Denied
    ... Check to make sure that it resides in both domain admins groups. ... Having a trust doesn't explicity grant you access to all, ... > I discovered that the Forest functional level on the test domain needed ... >> Is the access denied error caused by the type of trust I have created? ...
    (microsoft.public.win2000.active_directory)
  • Re: Access Denied to add wkstation to a domain.
    ... You need to enter the credentials for a domain administrator such as a ... member of the domain admins group or a user that has been delegated the task ... ten workstations to the domain and after that they can not any more. ... Client User Name: Administrator ...
    (microsoft.public.windowsxp.security_admin)