Re: Separating domain admins and enterprise admins



Hi Wolfk,
First off, Don't make anyone you don't trust or who doesn't follow policy a domain admin of any domain in your forest.
To understand what's going on with the reversion of permissions, you need to read about the "adminSDholder process"
A treatise I enjoy can be found here: http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx.
There are other links within the blog which also add info.

Regards,

Austin
"WolfK" <WolfK@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:89ECD566-3299-4857-AF2D-1A1E9B1C754B@xxxxxxxxxxxxxxxx
We want to separate the functions of domain admins and enterprise admins, so
the former cannot make themselves enterprise admins. When I do this in a new
AD created in newly installed 2003 R2 servers, the domain admins keep modify
perms rights, as they are the owners. So I change the ownership to
Enterprise Admins and put an explicit deny on the enterprise objects, which
are in their own OU. Within minutes some system process goes through and
restores the default permissions. What's the point of having separation of
rights when the system thinks it knows best? Beside that point, how do I
stop this behavior? Is there some security template somewhere that I need to
modify?

.



Relevant Pages

  • Re: isolating a subdomain in AD
    ... EVERY domain admin in the forest can take over control, ... > (Enterprise Admins are owners within the forest and can always take ...
    (microsoft.public.windows.server.active_directory)
  • Re: 2003 forest: accesing sysvol in child domain
    ... I'm logged on as a Domain Admin account from child domain which is also ... member of Enterprise Admins. ... GPO) unless logging on to one of the child DCs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: enterprise admins in single domain question
    ... Yes, a domain admin, or even a server operator of a child domain can add themselves to enterprise admins. ...
    (microsoft.public.win2000.active_directory)
  • Re: Domain Admin password changes
    ... Yes, by not making other members of domain admin or enterprise admins, and ... that is member of both enterprise admins and domain admins for several ... I recommend you to limit the workstations where domain ... My boss wants to set the default domain admin ...
    (microsoft.public.windows.server.active_directory)

Loading