Re: "Domain Admins", user account and privileges




<jwat@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:1170086696.304503.256560@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
This is a multi-part inquiry and hopefully all my questions get
answered.

1. Should a domain admin (user who is a member of the "domain admins"
group) also be a part of the "domain users" group?

Yes, and will be by default since practically all users of the domain
are inserted into that group automatically (unless special methods are
used to avoid this.)

a. If yes, how do I handle permissions for this user when
permissions for "domain users" are restricted?

Restricting permission are done with DENY, or by never granting
permissions at all -- and there are differences in the effect from an
owner or admin perspective.

Avoid DENY permissions in general, and especially on groups
applying to (almost) everybody, e.g., Everyone, Domain Users,
Users, Authenticated Users.

The trick to permissions is only to GIVE the permission necessary
and (almost) never use the DENY to try to take it away.

Remove references to Domain Users (etc), rather than trying to
deny on such groups.

Suppose I have
disabled on "write" access on a network shared folder. This user will
no longer have "write" access ...

Then GIVE permissions for READ (or some superset of READ) without
the write, rather than trying to deny it.

... to that folder because the most
restrictive policy applies.

Not true, but a common misunderstanding or misapplication of the "most
restrictive" to the WRONG place.

Most restrictive is only correct for when TWO ACCESS Methods are
involved, e.g., Share permissions and NTFS permission. User must have
"enough" at BOTH checks when coming through the network, this is where
the term most restrictive is properly applied.

Giving Read to Users, and FC to Admins in no way restricts the admins.

For one ACL (access control list), i.e., for one access method, the rule
is actually the opposite, the SUM of all permisssions for the user and the
users groups (as long as certain weird cases like DENY are not involved.)

2. This is a strange one: when the user is a member of "domain users"
he has the ability to add a local printer. When he is not a member of
"domain users" the add a local printer option is ghosted or grayed
out. This is due to GPO restrictions on the "Domain Users" group.

Interesting. Didn't know that but I have never seen anyone try to remove
Admins from Domain Users. (It's actually a bit tricky to do.) Don't do
that. <grin>

Any and all suggestions are welcome. Please clarify these issues for
me. Thank you.

Grant what you want them to have. And only what you want them to
have. Then you can always grant more through a different group.

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • Re: Exch 2003 mailbox permissions
    ... The deny is coming from Exchange ... itself.Exchange 2003 does not allow Domain Admins or Enterprise Admins to ... admin accounts if you want them to have full mailbox access. ... Try applying permissions at the server or admin group level in ESM. ...
    (microsoft.public.exchange.admin)
  • Re: How to catch someone reading other email accounts?
    ... But it does mean they can probably change the permissions to suit ... By default this behaviour is set to deny for Admins in Active Directory, ...
    (microsoft.public.exchange.admin)
  • Re: Programs and Group Policies
    ... > resides under the shared folder. ... >> If the NTFS permissions are more restrictive than the share permissions, ... and several other users with that are in the Domain Admins group on ... Indicating that Domain Admins are in the local ...
    (microsoft.public.windows.server.sbs)
  • Re: Delegate Control... Reset Passwords
    ... You can force replication to make the changes immediately to all DCs. ... want that Admins keep the users password. ... that Read and Write permissions in pwdLastSet attribute. ... >>> goal is to reset passwords for users in selected OU's, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Prevent changes to Administrator password
    ... Restricted Admins group to mitigate against what you propose Deji. ... This posting is provided "AS IS" with no warranties and confers no rights! ... you need to understand that permissions on the ...
    (microsoft.public.windows.server.active_directory)

Quantcast