Re: Domain Admin password changes



Yes, by not making other members of domain admin or enterprise admins, and
only delegate required permissions, how ever this is not a recommended way
to troubleshoot security issues, you will have to use a security context
that is member of both enterprise admins and domain admins for several
operations today. I recommend you to limit the workstations where domain
admins can logon, monitoring administrative workstations, lock down
administrative workstations.

--
Regards
Christoffer Andersson
Microsoft MVP - Directory Services

No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips

"Mike B" <Mike B@xxxxxxxxxxxxxxxxxxxxxxxxx> skrev i meddelandet
news:B4E95989-3DFA-43BB-98DD-80CB686B247B@xxxxxxxxxxxxxxxx
> We are running AD 2003. My boss wants to set the default domain admin
> password and put that password in a safe for security. The problem is
> that
> an domain admin can change that adminstrator password. Is there a way to
> prevent the default domain admin's password from being changed by anyone
> other than logging in as the domain admin?


.



Relevant Pages

  • Re: Mailbox store wont mount because EDB file not being created;
    ... The account I am using is a domain admin. ... Can anyone recommend the ...
    (microsoft.public.exchange.setup)
  • Re: Domain Users rights on local machine
    ... The domain Users are just members of the Users group. ... groups -> groups -> Power Users and add to the list of members the Domain ... Power Users Access, if yes how so? ... is a Domain Admin given ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: isolating a subdomain in AD
    ... EVERY domain admin in the forest can take over control, ... > (Enterprise Admins are owners within the forest and can always take ...
    (microsoft.public.windows.server.active_directory)
  • Re: 2003 forest: accesing sysvol in child domain
    ... I'm logged on as a Domain Admin account from child domain which is also ... member of Enterprise Admins. ... GPO) unless logging on to one of the child DCs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: enterprise admins in single domain question
    ... Yes, a domain admin, or even a server operator of a child domain can add themselves to enterprise admins. ...
    (microsoft.public.win2000.active_directory)