Re: Security on single forest domain design

Tech-Archive recommends: Fix windows errors by optimizing your registry



What do you mean? By delegating administration and not using the builtin
and default groups, e.g. backup operators and domain admins, you are going a
long way to securing AD. In addition to this, you should secure your
perimeter network and your servers and PCs. There's loads to discuss here,
so please post if you want specific examples, or have a specific question/
problem.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


.



Relevant Pages

  • Re: Domain account question
    ... using the outsource contractor has proven ... we have created a Domain 2 to keep the foreign domain admins ... we may be able to do this with Forest Trusts versus domain ... Windows Server 2000, which is not an issue as all DC's are ...
    (microsoft.public.windows.server.active_directory)
  • Re: 2003 ---> 2000 External Trust Issue
    ... MVP for Windows Server - Software Distribution ... > can add access perms for users from one domain to access ... > add domain admins group from 2K domain to domain admins on 2k3 domain ...
    (microsoft.public.windows.server.general)
  • Re: Domain account question
    ... is related to security and ITAR. ... Domain Admins as they are typically in foreign country's and that is a no no ... Windows Server 2000, which is not an issue as all DC's are ...
    (microsoft.public.windows.server.active_directory)
  • Re: Builtin groups
    ... > of the computers Backup Operators Group. ... >>Microsoft MVP for Windows Server - Management ...
    (microsoft.public.windows.server.general)
  • Re: Server 2003 SP1 Serious Flaw
    ... Tanveer ... > domain admins in the local administrators group on a windows server ... > SP1 and what it does regarding security. ...
    (microsoft.public.windows.server.general)