Re: Settle a Administrator's dispute
- From: "Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx>
- Date: Sun, 06 Aug 2006 17:08:43 -0400
It takes much less than administrator on a child DC to escalate all the way to Enterprise Admin of an entire multidomain forest. There is a reason the domain isn't considered a security boundary.
As for the specifics of how, not going to share it as there is nothing no one can do to really prevent it. It isn't all that hard to work out the steps when you think enough about it though.
--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net
---O'Reilly Active Directory Third Edition now available---
http://www.joeware.net/win/ad3e.htm
Jorge Silva wrote:
.It is moot, if a user is in Administrators or Domain Admins they can
give themselves as much rights as they want in the forest.
What do you mean? That a member of bulin/administrators can't add himself to Enterprise and Domain Admins in the Root?
If yes... I'm sorry but the last time that I tested this it worked... Of course I'm talking about Root domain and not Child domain, in child they can add himselfs to the Domain Admins.
- Follow-Ups:
- Re: Settle a Administrator's dispute
- From: Jorge Silva
- Re: Settle a Administrator's dispute
- References:
- Re: Settle a Administrator's dispute
- From: Joe Richards [MVP]
- Re: Settle a Administrator's dispute
- From: Jorge Silva
- Re: Settle a Administrator's dispute
- Prev by Date: Re: new user
- Next by Date: Re: Settle a Administrator's dispute
- Previous by thread: Re: Settle a Administrator's dispute
- Next by thread: Re: Settle a Administrator's dispute
- Index(es):
Relevant Pages
|
Loading