Re: Authenticated Users
- From: "Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx>
- Date: Fri, 13 Oct 2006 10:49:46 +0100
Hi
I agree with the other guys having authenticated users group has members of
the Domain Admins is not a good thing, and represents security issues for
all FOREST. It would be nice to urgently check why that is configured in
that way and for what.
--
I hope that the information above helps you
Good Luck
Jorge Silva
MCSA
Systems Administrator
"Richard Mueller" <rlmueller-NOSPAM@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:e9m9mNm7GHA.4568@xxxxxxxxxxxxxxxxxxxxxxx
"Tomasz Onyszko" <T.Onyszko_nospam_@xxxxxx> wrote in message
news:eH360Jk7GHA.4288@xxxxxxxxxxxxxxxxxxxxxxx
moyer wrote:
I am an IT Auditor.
We found the authenticated users group being a member of the Domain
Admins.
It has "send to" and "special" access. Also there are some other admin
apllication groups that it is assigned to with the same access.
I seems as if this is a issue, that this has been assigned while
installations have taken placed.
Can any body shed any light on this, and also is this security risk?
Somebody in this company really liked the shortcuts ... belive me that
authenticated users in Damain Admins group is security risk ... a big
one.
--
Tomasz Onyszko
http://www.w2k.pl/ - (PL)
http://blogs.dirteam.com/blogs/tomek/ - (EN)
Seems equivalent to having no security at all.
--
Richard
Microsoft MVP Scripting and ADSI
Hilltop Lab - http://www.rlmueller.net
.
- Follow-Ups:
- Re: Authenticated Users
- From: Tomasz Onyszko
- Re: Authenticated Users
- References:
- Re: Authenticated Users
- From: Tomasz Onyszko
- Re: Authenticated Users
- From: Richard Mueller
- Re: Authenticated Users
- Prev by Date: Re: IFM and Universal Security Groups
- Next by Date: Re: Setting "user must change Password at next logon" not working.
- Previous by thread: Re: Authenticated Users
- Next by thread: Re: Authenticated Users
- Index(es):
Relevant Pages
|