Re: Domain Administrator privs on Client



The Enable to delegation setting is quite something else.
If you have enabled that due to this reasoning you should reverse it.
That setting lets the accounts assume the credentials of others in
cricumstances where they have the token available.
This is a potential risk if given to any principal that is not regulated.

Restricted groups is the group policy way to dictate the complete
list of members in (of the memberships of) a group.
However, be aware that this is the full list and will replace any
other memberships.

One can set a machine startup script to check that Domain Admins
is still a member of its machine local Administrators group and if not
then add it. This leaves a window of time, between restarts, when
the Administrators might be altered, whereas Restricted Groups
for a member will in default circumstances have a window of about
90 minutes max.

"Tim Guy" <tim@xxxxxxxxxxxxxxxxxxxxx> wrote in message
news:ePpMwhXMGHA.2580@xxxxxxxxxxxxxxxxxxxxxxx
With Windows 2003 AD/Network, I can not get a domain administrator to
administor a local client / server. Only the local administrator will
work.

I always thought that the setting in windows 2000 GPOs to over come that
was "Enable Computer and User accounts to be trusted for deligation"

Doesnt seam to be on Windows 2003. What is the policy setting in a GPO to
get around this?

Cheers

Tim






.



Relevant Pages

  • Re: Archive useraccounts
    ... Regards ... They will be able to see the memberships ... >> disable the account we can move the users to an OU for disabled accounts. ... >> AD/Exchange admin, 2003. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Query disabled users and delete their memberof associations
    ... whole bunch of legacy disabled accounts (not pretty, ... If you remove the group memberships, what's the use of disabling the ... It cannot be modified on the user object and it is ...
    (microsoft.public.windows.server.active_directory)
  • dsquery and dsget output issue
    ... I am using dsquery to query AD for disabled user accounts. ... Now I want to remove the group memberships for them but want to back up ...
    (microsoft.public.windows.server.scripting)

Loading