Re: Moving DC's From Default OU ?



In an effort to secure the AD, we want to move these DCs and all
other
computer objects in to another tree structure so that we can apply a DENY
for
all permissions.

Make Sense? Hope so.

Heck no! if I'm an admin (domain admins, administrators, enterprise admin,
etc) you can deny whatever you want to. It will not work! Why? Because
although I don't have permissions (the DENY) I can change them back so I do
have access. How? Just by taking over the control! (take ownership and
change permissions again to whatever I want to)

this is like: THINKING you have a metal vault door, but in really it is a
plastic one and very easy to kick it down!

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Jim B." <Jim B.@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:37DE7758-3892-4CAE-BB07-7CA328800F2D@xxxxxxxxxxxxxxxx
Joe,

I've got one for you. My company is moving the production systems to a
utility computing environment that is hosted at a 3rd party data center.
The
3rd party will be managing the O/S and hardware for us. One of their
requirements is that we establish a trust to their management domain and
grant their management group access as members of the Built-in
Administrators
group on the DCs that they will be hosting for the production domains and
forest. While setting up a resource domain would be the preferred method,
it
is out of scope for this project.

In an effort to secure the AD, we want to move these DCs and all other
computer objects in to another tree structure so that we can apply a DENY
for
all permissions.

Make Sense? Hope so.

Jim

"Joe Richards [MVP]" wrote:

It can be done safely but the more important question is why? I have yet
in 6 years of hundreds of people in lots of companies trying to convince
me of this to have heard a single good reason for it.

In almost every case it the thought to do this is based on some
misunderstanding on how Domain Security works or some stupid plan to
have a pretty hierarchy.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Chris wrote:
Is there any known issues from moving our DC's from the default domain
controller OU?



.



Relevant Pages

  • Re: MMC - admin locked out too
    ... just use the Deny trick to exempt ... from an admin account before it can edit policy, ... > Limit access to Regedit, MMC, command line, etc. & ... > restrict such items to Administrators only. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Giving admins Local Admin to DCs not Domain Admins
    ... out permissions over the whole domain. ... Althought I can give the users PowerUser or LocalLogon rights via ... Can you with Server 2003 give a user just local admin to a DC ... but there's no such thing as local administrators ...
    (microsoft.public.security)
  • Re: MS Knowledgebase Article 298345-Cant delete file...
    ... Logging in as admin is not that important with NTFS. ... What is important is the the NTFS permissions have ... no grant to Administrators and the owner is also not ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Windows 2000 - Local policy - deny logon loccaly
    ... Map the Admin$ or C$ share as an admin, then set a Deny ... of Full for Administrators on system32\GroupPolicy in the ... > Local policy settings -- deny logon locally. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: MMC - admin locked out too
    ... I probably should have added that the Deny is used here ... granted to Administrators would also do this, ... and granted permissions for all of those other accounts. ... > the Deny column for the Full Control line. ...
    (microsoft.public.windowsxp.security_admin)