ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    active directory real defense for domain admins

    IT Discussion
    active directory security
    3
    6
    1.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AmbarishrhA
      Ambarishrh
      last edited by Ambarishrh

      Youtube Video

      1 Reply Last reply Reply Quote 0
      • C
        Carnival Boy
        last edited by

        Good stuff. I'm typical of a small shop IT manager in that I'm a Domain Admin but am totally unqualified to have such powers and tend to avoid doing anything for fear of breaking something.

        I have one question. He recommends setting Domain Admin logon restrictions to Domain Controllers only. So the DA is unable to logon to any other servers or workstations. This makes sense, I guess. However, if not Domain Admin, what kind of other domain account has local admin rights across the domain? For example, if I want to do something on a local workstation that requires admin rights, I currently logon as a DA. If I'm prevented from doing that, what should I logon as?

        AmbarishrhA 1 Reply Last reply Reply Quote 0
        • AmbarishrhA
          Ambarishrh @Carnival Boy
          last edited by

          @Carnival-Boy Having a Domain administrator account for the regular support tasks is not generally recommended. what I suggest is to create a normal account for these tasks and you can create a GPO targeted to all Computer Objects (excluding your servers) in your AD and add this account to the Restricted Group then this account will have admin access to all machines.

          For more details about the Restricted Group: http://www.windowsecurity.com/articles-tutorials/windows_os_security/Using-Restricted-Groups.html

          1 Reply Last reply Reply Quote 2
          • C
            Carnival Boy
            last edited by

            Thanks. I will do that.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              NTG has a "technician" group for local admin access to workstations.

              1 Reply Last reply Reply Quote 0
              • C
                Carnival Boy
                last edited by

                I just followed this:
                http://community.spiceworks.com/how_to/show/907-gpo-to-push-out-local-administrators-across-a-domain

                Two minute job and I'm all sorted.

                1 Reply Last reply Reply Quote 1
                • 1 / 1
                • First post
                  Last post