Security Basics mailing list archives

RE: Restrict the Domain Admin


From: "Brunner, Mark" <MBrunner () tor fasken com>
Date: Fri, 16 Sep 2005 16:42:41 -0400

Yes, you would delegate permissions using GPO's in Active Directory instead of making them Domain Admins.
This way you can be as granular as you want when assigning admin chores, using least privelidge.

-----Original Message-----
From: sf_mail_sbm () yahoo com [mailto:sf_mail_sbm () yahoo com]
Sent: Friday, September 16, 2005 6:12 AM
To: security-basics () securityfocus com
Subject: Restrict the Domain Admin


Hi List,
Is there a way to restrict access of a Domain Admin?

Example, can we allow a Dommain admin to do everything EXCEPT user management (e.g. password reset)? 

We want to secure our environment, and do not want to have "ALL-POWERFULL" domain admins around

Thanks for your suggestions

P.S. Environment: Windows (2000 & 2003) - Active Directory


Current thread: