Re: Need to Prevent Admins from Logging on to all servers

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi
Hum...
In fact you can do that. As others said, you can define polices that locks the domain Admins out of your servers, but... if they want... and because they have that privilege, they can override your policies or change them manually or in some scenarios the system will replace existing configuration protecting members off that group to ensure that they have the privileges that they must have.
Just because they have the power to do that doesn't mean that your company policy allows that someone with high privileges can do whatever they want in the domain, if a person cross the line and is caught, that person should be responsible for his/her actions. Now... as others said, trust only domain Admins security group to people that should have that right, and shouldn't bother to lock this or that because those people "are" trusted and responsible.

The other option is to remove the servers from the domain; of course this has other problems that may not serve your interest :)

--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

.



Relevant Pages

  • Re: securing critical member servers
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... The point is that you can not remove domain admins from an OU. ... we have a windows 2003 active directory and have a couple of servers ... remove regular domain admins from the possibility of administering ...
    (microsoft.public.windows.server.active_directory)
  • Re: Question about a trust relationship and terminal serices
    ... one on my internal network and one on a dmz. ... >on to servers in dmz.org. ... the int.org Domain Admins are set as members of the ... > Bob Grabbe ...
    (microsoft.public.windows.server.active_directory)
  • Restrict Desktop Administrators Issue
    ... I run a small Win2k native mode network with 28 servers, ... Since these guys are Domain Admins my policy restriction ... them out of the Domain Admins group or something else? ... My desktop guys need to be administrators on all the ...
    (microsoft.public.win2000.group_policy)
  • Restrict Desktop Administrators Issue
    ... I run a small Win2k native mode network with 28 servers, ... Since these guys are Domain Admins my policy restriction ... them out of the Domain Admins group or something else? ... My desktop guys need to be administrators on all the ...
    (microsoft.public.win2000.security)
  • Restrict Desktop Administrators Issue
    ... I run a small Win2k native mode network with 28 servers, ... Since these guys are Domain Admins my policy restriction ... them out of the Domain Admins group or something else? ... My desktop guys need to be administrators on all the ...
    (microsoft.public.win2000.active_directory)