Re: Prevent Admin Logon to RWW



it should be a simple matter, 'Do not allow 'Administrator' to logon from
outside our local subnet'. I adhere to this principal in all other items.
'Administrator' does not have RRAS rights, if I wish to VPN to a server I do
so using a less priveleged account, I may then use the VPN to RDP as
'Administrator', OR since the introduction of RWW RDP Proxy I would prefer
to 1st 'Connect to my computer at work' as a non-priveleged user and then
RDP to the server with elevated priveleges.

I consider the fact that _ALL_ SBS2003 systems suffer from this obvious
security issue a 'problem'.

"Joe" <joe@xxxxxxxxxxxxxx> wrote in message
news:e5btmo$b5s$1$8300dec7@xxxxxxxxxxxxxxxxxxx
SuperGumby [SBS MVP] wrote:
No, the domain admin account cannot be locked out of RWW. I have raised
this as an issue with MS, can't say there's been much reaction.

"spm" <nospam@xxxxxxxxxxxxxxxxxx> wrote in message
news:xn0emr386aln2g000@xxxxxxxxxxxxxxxxxxxxx
Is there a way to prevent the sbs2k3 administrator from logging on via
RWW? I want to allow domain users to logon via RWW, but not the domain
admin, for reasons of security.


To avoid confusion here, it's the built-in one that can't be locked
out. The best you can do is to put an enormous and computationally
unbreakable password on it, write it down, put it in a locked cash
box in a locked company safe and never use it. Having made a couple
of domain admins first, of course.

I've said before that I also disagree with MS on this. They say it is
to make sure that you can never be locked out of a server. I'd agree
that this is the reason, and it's also the reason many people won't
hang the WAN NIC of a Microsoft product directly onto the Internet.
I'm sure there are also more subtle ways into Windows, but this is an
obvious one. Personally, given the choice of travelling to fix a
server I'm locked out of, or rebuilding it after it's been cracked,
I'd prefer the former.

My preference is not to lock out the domain admins from RWW, but to
open RWW only via VPN and not to allow the admins to remote in. It's a
bit slower, but not much. That way, you can still do remote admin work
on workstations (I also don't allow admin TS except over VPN) but only
after supplying two passwords, the second after you're connected and
being logged by both firewall and SBS. The bigger the glare of the
spotlight the cracker has to operate in, and the more machines he has
to compromise to cover his tracks, the better. Oh, and the firewall also
logs to a third machine running a syslog daemon.


.



Relevant Pages

  • Re: Remote web workplace
    ... VPN rights have nothing to do with RWW ... Terminal Services rights have nothing to do with RWW ... A user with admin rights automatically has RWW rights and these rights ... We have a local domain administrator that has all the rights blah blah ...
    (microsoft.public.backoffice.smallbiz)
  • Re: Remote web workplace
    ... Restricting access for remote Web desktop on SBS/2003 ... Create two special Security groups (maybe called RWW Domain Users and RWW ... A user with admin rights automatically has RWW rights and these rights ... We have a local domain administrator that has all the rights blah blah ...
    (microsoft.public.backoffice.smallbiz)
  • Re: Remote web workplace
    ... changing the Admin Template has no effect on current users ... You should check the membership of the Remote Web Security Group and modify ... We have a local domain administrator that has all the rights blah blah ... network externally through RWW. ...
    (microsoft.public.backoffice.smallbiz)
  • Re: Remote web workplace
    ... VPN rights have nothing to do with RWW ... Terminal Services rights have nothing to do with RWW ... Remove the admin template from the RWW group before giving a user admin ... We have a local domain administrator that has all the rights blah blah ...
    (microsoft.public.backoffice.smallbiz)
  • Re: Security permissions bug or inheritant permissions??
    ... administrator, they are for all intents ... and purposes a domain admin and an enterprise admin. ... There is a ton of flexibility in the AD delegation model below native admin. ... > (domain admins) will remain as they are so they can do their job. ...
    (microsoft.public.win2000.active_directory)