Re: Child Local Administrators



Craig says...
Hi, sorry to refresh the time stamp on this posting, I was hoping
someone had some experience with the Microsofts Best practice for
delegating Active Directory Service Administration. Can anyone share
the similiar polictical battle when the owner of a Child domain in the
forest weree asking for such elevated rights. Is it safe to delegate
Domain Configuration and DC Administor rights (both of which are
members of the local administrators group in the child) to a seperate
business area without compromising the whole forest? I'm always nervous
becasue with these rights you have access to the child domains DC that
has SYSVOL, access to the file system where the AD database file(s)
etc... The problem is this seperate business area are only accountable
for the child domain not the forest.

I've posted the URL to the MS best practise.

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/actdid2.mspx


Hi Craig,

is it save to grant someone physical access to a DC? Or to your network?

Being save and secure is always a shade of gray - never black or white. Someone
who has physical or admin-access to a DC is always able to crack other accounts
on the box. Someone with domain admin rights is always able to gain domain or
enterprise admin rights in other domains of the forest.

However those tasks require the skill and criminal energy to do so.

I would prefer not to grant many admins write access to the configuration
partition, mainly to protect the ones which are not educated enough. If you
have admins of downlevel domains which need to preform tasks which require
access to the configuration partitions, check the ad delegation whitepaper and
KB if you are not able to delegate just the required parts.

And the bottom line is - decide depending on the skills of the admins and how
much you can trust them. If you can't trust them don't give them user-accounts
;-) If you can trust them but don't trust their skills delegate as strict as
possible and educate them how to perform those tasks.

--
Gruesse - Sincerely,

Ulf B. Simon-Weidner

MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz
Weblog: http://msmvps.org/UlfBSimonWeidner
Website: http://www.windowsserverfaq.org
.



Relevant Pages

  • Re: AD design question. 2 Domains vs. 2 OUs
    ... You can delegate these rights over OU trees. ... Your admins at these sites will ...
    (microsoft.public.win2000.active_directory)
  • Re: What are the user rights required in a domain to authorise DHCP?
    ... When I stated work around I was referring to whether or not there was a KB ... This posting is provided "AS IS" with no warranties, and confers no rights. ... required to delegate this right about 2yrs ago now.. ... If you want to delegate the right to Auth DHCP servers, ...
    (microsoft.public.windows.server.active_directory)
  • Re: What are the user rights required in a domain to authorise D
    ... my test setup. ... Santosh K. ... This posting is provided "AS IS" with no warranties, and confers no rights. ... required to delegate this right about 2yrs ago now.. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How does OU delegation work?
    ... A file system can contain two type of objects files and directories. ... When you delegate a group to have "Full Control" of computers objects, though, it doesn't imply that they will have admin rights on the actual computers those computer objects they represent, in the same way that delegating them "Full Control" of user accounts doesn't give them any extra right on the actual people (otherwise we would all be admins of the "hot blonds" OU right;) ). ... You can use a Restricted Groups setting in a GPO to achieve this or write a startup script that adds the account and link the GPO to the top level OU under which the departmental admins are kings. ...
    (microsoft.public.windows.group_policy)
  • Re: Grant Administrative Access to a Domain Controller
    ... * This posting is provided "AS IS" with no warranties and confers no rights! ... to delegate the appropiate rights. ... Controller Security Policy are also options to log on as a service, ... to domain controllers to restart services, ...
    (microsoft.public.windows.server.active_directory)