Re: AD and hidden admin shares

From: ptwilliams (ptw2001_at_hotmail.com)
Date: 11/15/04


Date: Mon, 15 Nov 2004 23:43:57 -0000

Yes. There's a reg key. However this is only a security issue if you don't
trust your admins, have too many users running as administrators, or are
using the same passwords for the non-domain local administrator accounts and
the domain administrator accounts.

These shares are there by design for a reason. They're very handy tools.
Do you really want to get rid of them??

-- 
Paul Williams
http://www.msresource.net
http://forums.msresource.net
"Saqib Ali" <rumionfire@gmail.com> wrote in message 
news:%23yokpBzyEHA.804@TK2MSFTNGP12.phx.gbl...
Hello All,
I have noticed that when a client machine joins the AD domain, the
ability to use  Simple File Sharing goes away, and the hidden admin
shares are available for remote connections (you have to connect to C$,
and only local administrators can do it).
The worst part is that even the machines that are not in the AD domain
can connect to C$ on any machine in the AD domain.
This can be serious security issue. Is there a way to stop admin shares
from automatically becoming available???
Thanks.
Saqib Ali
http://validate.sf.net 


Relevant Pages

  • SUMMARY WAS: OT? Philosophical Question on SA responsibilities
    ... helpful for managers interested in hiring new administrators. ... Would you go thru the 14,600 messages in root and admin ... If I was a new SA I would if encountering a security hole, ... I can see some use for the passwd -s part of the crontab script, ...
    (SunManagers)
  • Re: New Organizational Unit for a new remote office.
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... EVERY DOMAIN ADMIN IN THE FOREST ...
    (microsoft.public.win2000.active_directory)
  • Re: Rid AD of Circular Group Membership
    ... I'll try to keep this going; because it might be useful to another admin ... The quess is each has an account and uses it, ... part of stations) into the machine local Administrators group. ... Administrators Group has a members: ...
    (microsoft.public.windows.group_policy)
  • Re: MMC - admin locked out too
    ... just use the Deny trick to exempt ... from an admin account before it can edit policy, ... > Limit access to Regedit, MMC, command line, etc. & ... > restrict such items to Administrators only. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Trouble with admin access after creating trust.
    ... This makes sense since on the dc's the administrators group is given full ... This posting is provided "AS IS" with no warranties, and confers no rights. ... Because I am part of this domain admin group, ... Situation still exists - on the 2000 domain, I log on with an account ...
    (microsoft.public.windows.server.active_directory)

Quantcast