Administrator Accounts

Administrator Accounts

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Administrator Accounts Erl 07-11-2005
Posted by =?Utf-8?B?RXJs?= on July 11, 2005, 8:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
OK, I've looked around a quite a bit and haven't found any solid answers for
setting up security on administrator level accounts.

Here is the scenario...

We have 5 people who need to do different tasks on our Windows 2000 Domain

All 5 need to be able to add accounts, reset passwords, join machines to
domain.
3 need access to backups
2 need access to Exchange and AD - basically full access.

We would also like to audit these accounts so we can see who did what and
when.

These accounts will be used for admin type things only, all users have their
normal accounts for daily activities.

Can someone offer some suggestions or point me to a good resource?

Thanks,
Erl


Posted by Steven L Umbach on July 11, 2005, 12:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You need to be more specific in what you need the users to do with AD for
the 2 users. Full access may not be possible without making the users domain
administrators. Otherwise you can use delegation and/or privileged group
membership to accomplish much of what you want. For instance users of
backup operators group for the domain in Active Directory Users and
Computers can backup and restore domain controllers. There are also separate
user rights for backup and restore in Domain Controller Security Policy.
The backup/restore could also be granted for all domain computers if that is
your goal.

Members of account operators in ADUC can create user accounts and groups for
the domain or you can delegate authority to create users/computer accounts
and reset passwords for all but privileged group members. In other words a
user delegated that power could never reset a domain administrators
password. When you delegate for the domain/OU you can use standard or create
special permissions. The links below may help as examples of delegation
which is done via modifying AD object permissions with or without the wizard
which you can access by right clicking the domain or OU container and select
delegate control. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;221577
http://support.microsoft.com/default.aspx?scid=kb;en-us;315676
http://www.microsoft.com/windows2000/techinfo/reskit/deploymentscenarios/scenarios/ou_delegate_admin_authority_secgroups.asphttp://www.microsoft.com/windows2000/techinfo/reskit/deploymentscenarios/scenarios/ou_delegate_admin_authority_secgroups.asp

> OK, I've looked around a quite a bit and haven't found any solid answers
> for
> setting up security on administrator level accounts.
>
> Here is the scenario...
>
> We have 5 people who need to do different tasks on our Windows 2000 Domain
>
> All 5 need to be able to add accounts, reset passwords, join machines to
> domain.
> 3 need access to backups
> 2 need access to Exchange and AD - basically full access.
>
> We would also like to audit these accounts so we can see who did what and
> when.
>
> These accounts will be used for admin type things only, all users have
> their
> normal accounts for daily activities.
>
> Can someone offer some suggestions or point me to a good resource?
>
> Thanks,
> Erl
>



Similar ThreadsPosted
Duplicate Administrator accounts May 21, 2007, 1:23 am
Report on administrator user accounts.... January 25, 2007, 4:16 am
Built-in SID accounts??? November 3, 2006, 4:21 pm
user accounts November 28, 2007, 1:37 pm
AD accounts and wireless, VPN, Cisco ACS May 11, 2006, 5:19 pm
Locking user accounts when inactive August 22, 2005, 6:04 am
IIS 6 w/ NT 4.0 and Active Directory Domain Accounts October 11, 2005, 1:16 pm
IEEE 802.1x for Domain user accounts only May 21, 2007, 2:29 pm
Service accounts with password expiration August 15, 2008, 2:36 pm
How poor it is if I let parents share accounts with kids ? August 8, 2005, 5:45 pm

The site map in XML format XML site map

Contact Us | Privacy Policy