Jump to content

How to restrict changes to Domain Admin & Administrator Groups


Recommended Posts

Posted

Is there a way to protect W2003 AD Domain Admin & Administrator Groups so

existing members cannot add other users to these groups ?

 

I only want our Enterprise Admins group to have change rights to these groups.

 

I have tested

 

Created OU- Test,

Removed write permission for domain admins on this Test OU.

Blocked inheritance with exception of Enterprise Admins

Then moved Domainadmin group to this OU,

Removed write permission and removed self as member for this group

But after 1 hr all the settings are rolled back..

 

If this is not possible and Micirsift does not recommend this can you point

me to MS Documentation

 

I need to show our auditors this kind of change is not possible.

 

Many thanks - Stan

  • Replies 2
  • Created
  • Last Reply

Popular Days

Guest Robert Moir
Posted

Stan wrote:<span style="color:blue">

> Is there a way to protect W2003 AD Domain Admin & Administrator

> Groups so existing members cannot add other users to these groups ?</span>

 

Not reliably. Someone might come up with some hack but it's never going to

be foolproof (either this lock can be unpicked by someone with admin rights,

like uh... a domain admin... or it'll break other stuff).

 

Someone clearly misunderstands what administrators and domain admins groups

are for. If you don't trust people then they shouldn't be members of this

group end of discussion.

 

Auditors who don't understand this should be told to keep their nose out of

things that don't concern them.

Guest Shenan Stanley
Posted

Stan wrote:<span style="color:blue">

> Is there a way to protect W2003 AD Domain Admin & Administrator

> Groups so existing members cannot add other users to these groups ?

>

> I only want our Enterprise Admins group to have change rights to

> these groups.

>

> I have tested

>

> Created OU- Test,

> Removed write permission for domain admins on this Test OU.

> Blocked inheritance with exception of Enterprise Admins

> Then moved Domainadmin group to this OU,

> Removed write permission and removed self as member for this group

> But after 1 hr all the settings are rolled back..

>

> If this is not possible and Micirsift does not recommend this can

> you point me to MS Documentation

>

> I need to show our auditors this kind of change is not possible.</span>

 

Who cares about the auditors at this point?

 

If you have domain admins/administrator group members you cannot trust with

the power this gives them - they should not be in those groups at all.

That's a social/political issue - not a technical one.

 

Don't complicate a simple problem - those who cannot be trusted with extra

privs do not get extra privs.

 

--

Shenan Stanley

MS-MVP

--

How To Ask Questions The Smart Way

http://www.catb.org/~esr/faqs/smart-questions.html

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...