Re: prevent accidental AD objects deletion

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Phillip Renouf (PhillipRenouf_at_discussions.microsoft.com)
Date: 10/06/04


Date: Wed, 6 Oct 2004 10:45:05 -0700

If the Admin actually does need to have that level of access then you might
want to look at admin tools from NetIQ or Quest as both have the ability to
use a sort of Recycle Bin before permanently deleting the object(s). This can
save you a lot of hassles.

Phil

"Joe Richards [MVP]" wrote:

> 1. Make sure admins have two IDs, a normal ID and an Admin ID. That way they can
> browse AD without hurting it.
>
> 2. Only give them rights that they need for daily work and can handle.
>
> 3. Script all common tasks so that GUIs are not used to do the work and that
> business rules and checks/balances are enforced. The ultimate is to proxy the
> work through a website or some other mechanism so people don't need the native
> or delegated rights directly.
>
>
> It sounds like an issue with #2. I would tend to guess that whomever is likely
> to do that has too much in terms of permissions in the directory.
>
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
>
> PP wrote:
> > hi pple,
> >
> > is there any way to prevent domain admin from
> > accidentally deleting AD objects? ie OUs
> >
> > what sort of restriction should be imposed that will not
> > hamper daily administrative duties?
>



Relevant Pages

  • Re: Winform: Call a vbscript with elevated privileges
    ... It lets a "normal" user select one or more scripts to be run with ... Admin (sort of) privileges. ... use a different user account? ...
    (microsoft.public.dotnet.security)
  • Winform: Call a vbscript with elevated privileges
    ... It lets a "normal" user select one or more scripts to be run with Admin ... password of the Admin (sort of) account is enough. ... different user account? ...
    (microsoft.public.dotnet.security)
  • Re: Putty: Network error: No route to host
    ... Just to let you know that I have managed to sort the problem out. ... turns out that if I logged in as a Administrator then I'm able to ssh ... Admin right.Still somehow its not making any sense, ... To log in as a admin I pressed the "Delete key twice" while holding ...
    (comp.security.ssh)
  • Building a list from a list box selection
    ... that inputs the hours an employee works on certain projects and ... admin categories per week. ... Right now i have two list boxes that display ... and generate some sort of list below. ...
    (comp.databases.ms-access)
  • Re: checkpoint firewall -1 sp3
    ... Wake up, it's SP6 right now... ... Helmut ... NT Admin on his quest for experience! ...
    (comp.security.firewalls)