Re: Restrict Access



Thank you anthony. I appreciate your thoughts and input. You've offered
other options that I'd not considered and confirmed others that I had.
Have a great week and thank you again for your suggestions.
Mark


"Anthony" <anthony.spam@xxxxxxxxxxxxxx> wrote in message
news:Oam3igruGHA.4160@xxxxxxxxxxxxxxxxxxxxxxx
Really you have a business policy problem and a logical dilemma
masquerading
as a technical problem. The company wants the DB's to be "off limits" and
also wants the Enterprise Admins to run everything. Just give the
Enterprise
Admins a formal notice that accessing the data is a dismissal offence.
But I think you already realise this from the things you have looked at.
Obviously an Enterprise Admin can take the rights of any user in the
forest,
so you would need to make sure that no user account had the rights to even
read the data.
This means that you would need to use a completely separate unconnected
security system. You would also need to make sure that the credentials
required to access the DBs were not stored in any user account, and were
not
retained in any cache on any PC uses to access the system. So your
solution
is:
- Separate Forest, no trust of any kind.
- Access only though something like an SSL VPN, browser cache cleared on
logoff
- Two-factor authentication with one-time token, something like SecureID
This is not an odd solution. It is exactly the same as if you were trying
to
create a new system with reasonably secure access.
Anthony


"mwheat" <mwheat28@xxxxxxxxxxxxxxxxxx> wrote in message
news:uqKTZcnuGHA.5076@xxxxxxxxxxxxxxxxxxxxxxx
Good afternoon. I'm hoping someone has a suggestion for how to proceed
on
this as it doesn't quite fit any scenarios I've dealt with before.

Can we restrict management and access to servers in Active Directory
from
upper level enterprise admins?

Scenario:
Company A is has multiple database servers that need to be protected due

to proprietary information. Company B has acquired company A and agreed
that all DB servers are off limits to company B. They are migrating all
users and objects from A into a new OU in company B's Active Directory.
The concern is trying to restrict upper level enterprise admins from
having access or changing permissions on those boxes. All users from
company A will still need access to the DB servers.

Sorry for the somewhat confusing scenario. We've noodled the possibility
of creating a separate network space and restricting access by ACLs and
rules. Alternatively we could remove these machines from the new domain
and create a new one with a non-transitive trust. Then lock it down with
group membership.
Both seem to have pros and cons.

Any assistance would be greatly appreciated.
MW





.



Relevant Pages

  • Re: Restrict Access
    ... This means that you would need to use a completely separate unconnected ... Can we restrict management and access to servers in Active Directory ... The concern is trying to restrict upper level enterprise admins from ...
    (microsoft.public.windows.server.active_directory)
  • Re: Controlling access to MSTSC.exe
    ... to get through the windows firewall. ... static configuration by using VLANS in conjunction with a VLAN Policy Server ... > programs where I will need the ability to restrict by ... >>> level policy (i.e. who can connect via remote desktop to the servers). ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Not able to connect
    ... The ntp.conf file I appended was installed by the Fedora Core 5 installation except for the NIST servers which were added by the system date/time s/w under Fedora Core 5. ... The port number on your system is arbitrary, and is usually chosen at random by your system each time the client program prepares to make a request for the time. ... How can I tell if ntpd is working and keeping the clock synched? ... You may wish to restrict the pool to your geographic area. ...
    (comp.protocols.time.ntp)
  • Re: Restrict Access
    ... Really you have a business policy problem and a logical dilemma masquerading ... also wants the Enterprise Admins to run everything. ... Can we restrict management and access to servers in Active Directory from ... that all DB servers are off limits to company B. They are migrating all ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cant copy-paste files/folders
    ... Separate servers, on separate ... Only thing in common with the two servers though, ... We cannot copy / cut and paste in Windows. ... also copy when connecting to a shared folder from a workstation. ...
    (microsoft.public.win2000.registry)