Re: Co-Administrator



tatat wrote:
Using the built in Encrypting File System (EFS) it's possible to
restrict access to the point that administrators cannot read the
files without the proper account password. Learning curve is a bit
steep. Practice on a workstation until you get the hang of it.


Leaks like a seive. All the admin (or anyone else) needs is one of the
encrypting certs or the recovery cert. Oh, and the admin is also the
Certificate Authority Manager, so exporting any cert issued by it is
trivial.

Not that it's not possible, just that using built in CA still has the Domain
Admin still in control (by default).



Best practices for the Encrypting File System:

http://support.microsoft.com/kb/223316



"Charles" <Charles@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:07ECA812-C39E-4A01-83B2-9A864524AB34@xxxxxxxxxxxxxxxx
Hi,

I would like to grant admin rights with a young colleague so that he
can help me with all the IT stuff. Problem: there are certain shared
folder containing sensitive info that he cannot access now -- and I
would like it to
stay that way. Is there a simple way to give him enough rights to do
the IT
admin work, while keeping him from given shared folders?

So far this is what has kept me from granting him admin rights, so
any help
appreciated;

Charles

--
/kj


.



Relevant Pages

  • Re: Permissions (EVERYONE POST TO THIS)
    ... Removing Admin rights from your users is the prudent thing to do. ... without the IT Administrator providing these services and applications. ... priveledes, and before you know it, you have lost control of your network. ...
    (microsoft.public.win2000.security)
  • Re: I turned off UAC
    ... The User Access Control (UAC) can detect rootkits before they install. ... escalated to admin rights, the escalation to full-admin rights only last for the moment of escalation to do the task, and then the admin user is returned to being a Standard user again with Standard user rights only, not admin rights. ... Malware or a virus can only run under the context of the user account that is using the computer. ...
    (microsoft.public.windows.vista.general)
  • Re: XP & W2K server User rights need help
    ... accounts. ... This narrows the issue, since any admin ... > Here is another fact, this domain server had to be> replaced so a new one was created, in the old domain> server non of the users had accounts only the computers ... >>> Accounts in AD Power users with admin rights to local ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Running Applications and Adming Rights
    ... Again, I didn't give the Domain Admin rights, I am an application developer ... access rights for the install. ... >> the application folders, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Assigning applications to clients with USER GROUP privilege
    ... > installed when a computer account belongs to the "user group" ... quite happily when users have no admin rights whatsoever (which is annoying ... rather than assigning applications, honestly. ...
    (microsoft.public.windows.server.sbs)