Re: Secure Domain Contollers at Branch Offices

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Yes, but I think the answer really depends on many more factors than you
mentioned.
For example, what exactly is deployed on these domain controllers? Why are
they domain controllers? Are they locked rooms? Do these admins have
physical access to the domain controller machines? Why are the local site
administrators restarting services(this may fit with question 1)? What does
security mean to you? What does compromising "too much" mean in that
context?



There are more, but that's the base set of questions I think. Answers to
that should help guide the remainder of questions and help you get to a more
secure stance.

Al


"Bob Smith" <BobSmith@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:B933D7DE-F6BD-4A3F-B6D6-0FF21355FC43@xxxxxxxxxxxxxxxx
We need to reduce the number of users in the Domain Admins group. We are
running Windows 2003 and are not looking to move to the next release for a
while. We have multi-function domain controllers at a number of branch
offices. Administrators have been placed in the Domain Admins group to
administer these servers.

How can we remove admins from the Domain Admins group but still allow them
to perform daily operations tasks on these servers (restart services,
setup
printers, logon locally, manage file security... etc). Has anyone come up
with a good security model for this without compromising security too
much.

Thanks



.



Relevant Pages

  • Re: User get access denied error when prompted to change password adte Reset
    ... If you enable auditing of account management in the ... Domain Controller Security Policy, you may find useful info in the security ... make sure that the domain controllers do NOT have the ...
    (microsoft.public.win2000.security)
  • Re: Continual errors - Event ID 1030 and 1058 on DC
    ... This article will help you check the security rights on the sysvol ... Domain controllers have the read and apply rights to the Domain ... Controllers Policy. ...
    (microsoft.public.windows.group_policy)
  • Re: Blocking port scans on local network
    ... You can implement enumeration of SAM accounts and shares with probably no ... on domain controllers via Domain Controller Security Policy depending of ... domain computer that has a "require" ipsec policy assigned to it. ... between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • Re: Can not figure out why?
    ... every second on the domain controllers. ... Want some good security information? ... Logon Failure: ... I checked all service and none of service uses administrator account ...
    (microsoft.public.windows.server.active_directory)
  • Re: Audit Admnistrators
    ... You can enable auditing for various categories on domain controllers via ... Domain Controller Security Policy such as for account management, ... and directory services. ...
    (microsoft.public.security)