Re: Automating Local Computer Admin Rights



10 DAs would be about right if you had maybe 500,000+ employees and about 1000 DCs. I ran a 250k user environment with 3 Domain Admins and no "fake" domain admins by giving that many rights.

I would actually not try to skirt the intent of the audit because they may come back and bust you again, I have been through the external banking audits and the auditors aren't all stupid. You almost certainly don't need that many people with that many rights in the directory. Usually that is done only when people don't really know how to manage AD properly.

As for your last question, you want to look at Group Policies.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



xJayboyx wrote:
I work for a bank that currently has Six Banks under the holding company. So there is approximately 10 or so “Administrators” for our WAN. Now we have had examiners chewing us out for having to many users in the “Domain Admins” group. So we have went ahead and created a different group that basically has the same amount of right as the Domain Adims , but this way we don’t have the “Domain Admins” group full of users.

Now my Question Is: Is there a way in a Policy of some sort that I can make this new Group that was created a local Admin for each PC without me having to touch every single computer??

- Thanks for any input.


Jason

.



Relevant Pages

  • Re: Unable to prevent OU deletion by Domain Admins?
    ... That's how ACLs work, or at ... Microsoft's own guidelines for parsing ACLs states that DENY ACLs ... I understand that domain admins have the delete and delete subtree ... I have a folder where Domain Users have Full control rights. ...
    (microsoft.public.win2000.active_directory)
  • Re: Prevent changes to Administrator password
    ... To add to what I already said: *ANY* member of a Domain Admins group *MUST* be trusted in what he does with his account. ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ...
    (microsoft.public.windows.server.active_directory)
  • Re: Log on Locally
    ... even if I do not have the rights to log on locally, ... > Logon to the machine as a standard user and use the runas command. ... > snapin to reset the policy. ... I didn't check very well and I add Domain admins to ...
    (microsoft.public.win2000.security)
  • Re: Delegate certain rights to a single Domain Controller
    ... Please note that this hack does not eliminate all possible security risks, ... > This posting is provided "as is" with no warranties and confers no rights ... >> If you think your domain admins can only modify stuff in their own ... >>> cannot modify DCs across domains. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Mailbox Security
    ... >> How did you convince him with Notes? ... >> By default I believe Domain Admins are given DENY rights to FULL ACCESS ... >> I don't see anyway of convincing him that you cannot read the emails. ...
    (microsoft.public.exchange.admin)