Re: Account Operators accessing other account operators
- From: "Cary Shultz" <cwshultz@xxxxxxxx>
- Date: Fri, 10 Feb 2006 16:24:49 -0500
Matt,
I can almost guarantee you that JoeR is N*O*T going to post the 'How to' on
this topic. Pretty much no one will.
Not trying to be rude, but this is the type of stuff that the 'script
kiddies - or, Jr. Sys Admins' get their hands on and then wreck havoc in
their environments. And then it comes out that an MVP posted this 'How to'.
That would not be a good thing.
There are a couple of seemingly good security books on Active Directory that
would probably give you hints along the way. I say 'seemingly' becuase I
have not read them. So, I do not really know for sure.
--
Cary W. Shultz
Roanoke, VA 24012
"Matt" <Matt@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4EAF1F29-3048-4363-98C3-8A6F6475D3EA@xxxxxxxxxxxxxxxx
Thanks for all the reponses. I will have a look at delegation when I get
a
chance. Yes our helpdesk users were account operators from our NT days
and
it seemed convenient. We have about five OUs at the top level and I was
hoping to avoid having to delegate permissions on each OU (tree) and the
subsequent job of managing and troubleshooting delegation.
I was interested in the comment "if the acc ops are bright enough, they
can
give themselves Domain and Enterprise Admin rights anyway. That is why you
want to use delegated accounts for AD data admins." How can they do this?
They do not appear to have access to their own accounts or anything above.
Obviously I do not want them to be able to do this (although I think that
I
am safe with our helpdesk) so am interested in how they can do it.
Thanks.
.
- References:
- Account Operators accessing other account operators
- From: Matt
- Re: Account Operators accessing other account operators
- From: Jorge de Almeida Pinto [MVP]
- Re: Account Operators accessing other account operators
- From: Joe Richards [MVP]
- Account Operators accessing other account operators
- Prev by Date: Re: User Login Time on windows 2000 profesional on Domain
- Next by Date: Re: How to restore Domain Controllers that have been down for a long t
- Previous by thread: Re: Account Operators accessing other account operators
- Next by thread: Re: Account Operators accessing other account operators
- Index(es):
Relevant Pages
|