Re: Forest = Security Boundary?

Tech-Archive recommends: Fix windows errors by optimizing your registry




"Gabriel/TFI" <GabrielTFI@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E19FEB8D-9A03-47AA-B17C-97F2C5377F07@xxxxxxxxxxxxxxxx
I am reading the great book "Active Directory 3rd Edition" by Joe Richards
&
Co.

Maybe Joe will (also) responds; his is one of the most helpful posters on
the AD groups.

In Chapter 8, "Designing the Namespace", it is said that "The Forest, not
the domain, is the security boundary for AD. Anyone with high-level access
rights on any domain controller in any forest can negatively impact or
take
control of any other DC or domain in the forest".

I thought that the domain was the security boundary! :-(

It is, but only sort of, or in certain ways. The problem and the confusion
is that with trusts the boundary gets extended to all TRUSTED domains,
and since all of the domains in a forest trust each other the boundary in
some real sense expands to encompass the entire forest.

- Does this mean that delegating administrative privileges over domains
(e.g. different BUs) is a bad practice?

No. It just means that your have to recognize that you aren't achieving
"complete autonomy" as long as you are in the same forest.

- How can an evil-administrator of a child domain compromise another
domain
or the entire forest? What tecniques can be used to achieve this?

There are a variety of things -- let's see if Joe will post a list....

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • Re: LDAP
    ... Any DC in the forest will be able to authenticate any user in that forest. ... However, if you want good performance, then point your app at a GC, as Joe ... WRT schema master question -- schema master is only contacted for schema ... Hopefully you can configure the AIX box to ...
    (microsoft.public.windows.server.active_directory)
  • Re: Mulitple domains through Same MMC
    ... A DC will only have objects for the 2 forest partitions ... Alternatively make your own GUI tool to display the info, ... Joe Richards Microsoft MVP Windows Server Directory Services ... > dopmain in the same MMC untill added through snap-ins? ...
    (microsoft.public.win2000.active_directory)
  • Re: Creating 1st Active Directory
    ... Listen to Joe. ... Herb Martin, MCSE, MVP ... A single forest or an Exchange resource forest. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Infrastructure Master FSMO role, Global Catalogs and Forest Trusts
    ... Thanks to Herb, Paul, Jorge and Joe for the great answers and discussion. ... References to object external to the forest are represented as ... case - what does the IM do with cross-forest trusts? ... domains in a forest by comparing data in a domain against data in a GC ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegate certain rights to a single Domain Controller
    ... "If Joe says it can not be done, that is all I need to know!". ... Joe could very easily post how a Domain Admin can ... take over an entire forest, but that would not be very responsible. ... >>> cannot modify DCs across domains. ...
    (microsoft.public.windows.server.active_directory)