Re: Restrict User account creation




"Net Admin" <NetAdmin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5A6CE90D-6413-4A35-ACC9-4E034543C134@xxxxxxxxxxxxxxxx
I know that Domain Admins are the Gods of the domain but I must ask this
question..
Has anyone found a way to restrict a Domain Admin member from creating new
user accounts?

Of course not. Domain Admins have the right to take ownership of any
object so even if you apply restrictions they can just take ownership and
put it back.

Even then they can install drivers and services that work as part of the
System (or debug existing processes) and with enought cleverness and
tools get around most anything.*

*Maybe not "EFS encrypted files" if the specific admin is not also an
Encryption Recovery Agent. But even then the Admin could log on
as someone else (by first changing the password) and thus become either
the user or the recovery agent -- unless you have carefully removed the
private key for all the Recovery Agent cert(s) from all machines where
the resource might be located.

If not then I will demote this person to Domain User and delegate the
neccessary rights.

Correct. It is easier in almost all cases to never GIVE the excessive
privileges but only give those necessary and avoid trying to remove the
excess.

Thank you


.



Relevant Pages

  • Re: Domain Admins restriction
    ... > There is no such thing as a restricted domain administrator. ... >> few user files I want to restrict him from. ... >> I tried Domain Admin to the folders and then adding ... >> his name to these folder and restricting access, ...
    (microsoft.public.win2000.active_directory)
  • RE: Restrict the Domain Admin
    ... Give one set of rights to internal audit and another to ... Have a change process to get access to the domain admin account on the ... Subject: Restrict the Domain Admin ... Aren't these proceedural controls and not technical? ...
    (Security-Basics)
  • Re: Restrict User account creation
    ... Even if you find a way to restrict him as domain admin, he also has the right to undo your restrictions. ... So make him normal user and delegate control. ... neccessary rights. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Restrict Domain admins for Remote Desktop
    ... restrict users in same groups then either set up another security group, ... Administrators from using Remote Desktop onto my computer. ... want to restrict a domain admin and an administrator without ... restricting myself as I am also a domain admin and administrator. ...
    (microsoft.public.windowsxp.general)
  • Re: Client Access Rights
    ... This would only be a problem if the users in question had domain admin ... rights. ... > Note that while this will work in general, ultimately you can not restrict ... > separate domains or better yet separate forests. ...
    (microsoft.public.cert.exam.mcse)