Re: Problems with AdminCount bit, inheiratance, and email

Tech-Archive recommends: Fix windows errors by optimizing your registry



My experience here is that the best practice is to have separate operational
accounts for your DAs that aren't receiving email or doing "regular user"
stuff. The people who are DAs would have regular accounts that they use for
their normal work in the company.

The goal is that your DAs only use their DA accounts when absolutely
necessary, but they should generally never be logging into their
workstations to read email as a DA. That's super dangerous from a security
standpoint.

Joe K.

"Paul Williams [MVP]" <ptw2001@xxxxxxxxxxx> wrote in message
news:ek87BfAKGHA.2248@xxxxxxxxxxxxxxxxxxxxxxx
Any idea about why we're being told that DA's should NOT have email
accounts. I can't figure that out...

Can you elaborate on what they are saying/ suggesting?

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net




.



Relevant Pages

  • Re: SBS2008, Exchange, Outlook 2007
    ... A mail contact does not have a mailbox, so mail will be routed to the PrimarySmtpAddress. ... You need to create mailboxes to collect mail for such addresses, which also creates associated user accounts. ... All User Mail Box accounts are receiving email via OWA. ... We use Outlook 2007 as our email client. ...
    (microsoft.public.exchange.setup)
  • SBS2008, Exchange, Outlook 2007
    ... All User Mail Box accounts are receiving email via OWA. ...
    (microsoft.public.exchange.setup)
  • Re: Accountability of Domain Admins
    ... with the other DAs. ... > Upper management is unresponsive, but that is due to somewhat legitimate ... I absolutely agree that we should (if we kept all DA accounts), ... > have no authority to dictate the change, and I would be met with hostility ...
    (microsoft.public.windows.server.security)
  • Re: Problems with AdminCount bit, inheiratance, and email
    ... I get it...it's not that there is a technical problem with a DA having ... an email account--it's a security thing. ... The people who are DAs would have regular accounts ...
    (microsoft.public.windows.server.active_directory)
  • Re: Modify registry via Group Policy
    ... Two regular accounts were moved about ... Another regular user account was moved about a week ago. ... "Meinolf Weber" wrote: ...
    (microsoft.public.windows.group_policy)