RE: Domain Admin access on only a few servers??
From: Phillip Renouf (PhillipRenouf_at_discussions.microsoft.com)
Date: 02/10/05
- Next message: Dave B: "Export Usernames and Email Addresses"
- Previous message: TKO: "How can I remove/demote DC from AD if the server no longer exists?"
- In reply to: Allen Firouz: "RE: Domain Admin access on only a few servers??"
- Messages sorted by: [ date ] [ thread ]
Date: Thu, 10 Feb 2005 08:05:02 -0800
Definitely agreed. I would contact the vendor and find out exactly what
rights their service account needs then I would create them an account and
delegate only those rights to it that they specify they require.
Definitely avoid giving domain admins to a service account if you can avoid
it.
Phil
"Allen Firouz" wrote:
> John:
>
> I am always leery of making anyone a Domain Admin, especially an outside
> vendor. The ramifications can be huge and rarely good. Questions to ask
> from them is: why do they need Domain Admin rights? What tasks do they need
> to perform domain-wide? How does their system interface with AD?
>
> Based on their feedback and with planning, you can create delegate specific
> control to them using the Delegate Control feature > custom and assigning
> specific rights to them. Additionally, you can create a custom MMC and
> distribut it to them that only gives them access to the servers they need and
> nothing more.
>
> I would still recommend completely against Domain Admin access for outsiders.
>
> -Allen Firouz
>
> "John Taylor" wrote:
>
> > Our company has purchased a medical software system which included 3
> > Dell servers. They say they need to have domain admin level access.
> > We have given them local admin access on those 3 servers and are not
> > too fond of giving them domain admin access as they would be able to
> > access any of our network servers.
> >
> > Is there a way to give them domain admin level access but only somehow
> > restrict them to those 3 servers?
> >
> > Thanks,
> > -John
> >
> >
- Next message: Dave B: "Export Usernames and Email Addresses"
- Previous message: TKO: "How can I remove/demote DC from AD if the server no longer exists?"
- In reply to: Allen Firouz: "RE: Domain Admin access on only a few servers??"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|