Re: delegation for "Server Operators" on Member Servers

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



DCs really shouldn't be delegated to lesser admins. Anything that allows a lesser person to futz with services (other than simple stop/start), files, and processes on the machine opens you up for compromise and privilege escalation.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm

============================================================================
Do not read this worthless blog entry on
Defending Security Infrastructures http://blog.joeware.net/2006/07/11/445/
I'm serious, you will learn absolutely nothing about
Defending Security Infrastructures.
============================================================================

Daniel Sorokins wrote:
Thank for you response. its important your comment.
I need for a group of user (in all servers windows 2000: dc or members):

stop and start services.
kill process
restart computer.
this group of users support "problems" 7x24 (not software install-no fixes install-no adm AD) but if exist a problem with a process, they should repair the problem (stop, start, kill, reboot).

I view "complex" setting ACL for each services with GPO (Dc GPO and members servers GPO).

Thanks


"Joe Richards [MVP]" wrote:

You know that a server operator on a DC can become an Enterprise Admin pretty much anytime they want to right?



--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm

============================================================================
Do not read this worthless blog entry on
Defending Security Infrastructures http://blog.joeware.net/2006/07/11/445/
I'm serious, you will learn absolutely nothing about
Defending Security Infrastructures.
============================================================================

Daniel Sorokins wrote:
What is the recomendation for create server operator rol on members servers.

I need:

change time (I think use GPO - user right)
down server ( GPO- user right)
kill process ( act as op sys- user right)
stop and start all services ( gpo services acl?.....)
schedule task (gpo user right)

I use AD "server operator" rol with DC servers, but my IT Security Group request create this new rol with the minimum rights.

thank for comments.
.



Relevant Pages

  • Re: delegation for "Server Operators" on Member Servers
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... stop and start all services (gpo services acl?.....) ...
    (microsoft.public.windows.server.active_directory)
  • Re: delegation for "Server Operators" on Member Servers
    ... You know that a server operator on a DC can become an Enterprise Admin pretty much anytime they want to right? ... Defending Security Infrastructures http://blog.joeware.net/2006/07/11/445/ ... stop and start all services (gpo services acl?.....) ... I use AD "server operator" rol with DC servers, but my IT Security Group request create this new rol with the minimum rights. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need Help Understanding Kerberos SPN Problem
    ... When you see a message of server down with an application that uses a specific port, the port not responding is a server down to the clients. ... Joe Richards Microsoft MVP Windows Server Directory Services ... Defending Security Infrastructures http://blog.joeware.net/2006/07/11/445/ ...
    (microsoft.public.windows.server.active_directory)
  • Automatic Updates options are greyed out, SBS 2003 and WSUS
    ... The SBS server is the DC ... GPO: Default Domain Policy ... Computer Setting: 50 ... GPO: Default Domain Controllers Policy ...
    (microsoft.public.windows.server.sbs)
  • Re: SCW question.
    ... Created a new Server and installed IIS. ... and saw that the default rights for IUSR and IWAM users are there. ... Server to the domain without and GPO's applied...Local Security policy ... rights (which coincides with my Member server GPO settings). ...
    (microsoft.public.windows.server.security)