Midtown Computer Systems Enterprise

Convenient web based access to our favorite computer related Usenet groups.
MCSE.MS is not affiliated with Microsoft corporation, Cisco corporation, Oracle, CompTIA or any other vendor.
Check our Computer Hardware forum | Cell Phones reviews

Go Back  MCSE > Microsoft software reviews > Windows 2000 review > Active Directory
This is Interesting: Free Computer Magazines Now Free shipping to

Active Directory microsoft.public.win2000.active_directory

 
 
Thread Tools Display Modes
  #1  
Old 06-03-04, 04:13 AM
Jason
Restrict Desktop Administrators Issue
I run a small Win2k native mode network with 28 servers,
400 desktops and 6 desktop administrators. All desktop
admins are members of the Domain Admins group.

Due to a recent change in the security policy I've been
told to restrict my six desktop admins yet still allow
them to administer all of the desktops, for desktop
support purposes.

I want to restrict them from logging onto the servers and
managing user accounts. I do not want to stop them from
managing, configuring and administering the users desktops.

My earlier attempts to get this done has failed!!! I've
added the desktop support people to a new group
named "Desktop Support" and then I created a new group
policy which denies them log on access to the servers OU.
Since these guys are Domain Admins my policy restriction
is not working. They can still logon to the servers.

I thought that the deny permission was supposed to take
priority over the allow permission. Please help as I'm
being pressured to deliver a solution on this security
threat.

I passed the Win 2k Server Exam so I'm not at a total loss
of NTFS permissions. I just don't know what I'm doing
wrong here. Does this require changing ADSI info, taking
them out of the Domain Admins group or something else?

My desktop guys need to be administrators on all the
desktops whenever they logon with their account, but I do
not want them to be able to perform any account management
or server administration.

Thanks,

Jason
  #2  
Old 06-03-04, 06:10 AM
slashsupport slashsupport is offline
Junior Member
Join Date: Jun 2004
Re: Restrict Desktop Administrators Issue
If u still await for the solution i can give one
  #3  
Old 06-03-04, 06:12 AM
Shenan Stanley
Re: Restrict Desktop Administrators Issue
Jason wrote:
> I run a small Win2k native mode network with 28 servers,
> 400 desktops and 6 desktop administrators. All desktop
> admins are members of the Domain Admins group.
>
> Due to a recent change in the security policy I've been
> told to restrict my six desktop admins yet still allow
> them to administer all of the desktops, for desktop
> support purposes.
>
> I want to restrict them from logging onto the servers and
> managing user accounts. I do not want to stop them from
> managing, configuring and administering the users desktops.
>
> My earlier attempts to get this done has failed!!! I've
> added the desktop support people to a new group
> named "Desktop Support" and then I created a new group
> policy which denies them log on access to the servers OU.
> Since these guys are Domain Admins my policy restriction
> is not working. They can still logon to the servers.
>
> I thought that the deny permission was supposed to take
> priority over the allow permission. Please help as I'm
> being pressured to deliver a solution on this security
> threat.
>
> I passed the Win 2k Server Exam so I'm not at a total loss
> of NTFS permissions. I just don't know what I'm doing
> wrong here. Does this require changing ADSI info, taking
> them out of the Domain Admins group or something else?
>
> My desktop guys need to be administrators on all the
> desktops whenever they logon with their account, but I do
> not want them to be able to perform any account management
> or server administration.


Take them out of Domain Admins.
Make a new group, put them in it.. Push out that group to be loacl admins on
all Workstations. (Group Policies, Startup Scripts, Logon Scripts, PSEXEC,
SMS or whatever your favorite method is..)

--
<- Shenan ->
--
The information is provided "as is", with no guarantees of
completeness, accuracy or timeliness, and without warranties of any
kind, express or implied. In other words, read up before you take any
advice - you are the one ultimately responsible for your actions.


  #4  
Old 06-03-04, 06:12 AM
Andy Cadley
Re: Restrict Desktop Administrators Issue
The easiest way is as follows.

1) Remove them all from the Domain Admins group
2) Delegate any required AD privileges (Create Computer Objects etc) on the
OU containing the workstations.
3) Use the Restricted Groups section of Group Policy to add Desktop Support
to the local Administrators group on the individual workstations.

Hope that helps,

AndyC

"Jason" <sittingbull7@hotmail.com> wrote in message
news:b0b3780f.0406030004.41bb6383@posting.google.c om...
> I run a small Win2k native mode network with 28 servers,
> 400 desktops and 6 desktop administrators. All desktop
> admins are members of the Domain Admins group.
>
> Due to a recent change in the security policy I've been
> told to restrict my six desktop admins yet still allow
> them to administer all of the desktops, for desktop
> support purposes.
>
> I want to restrict them from logging onto the servers and
> managing user accounts. I do not want to stop them from
> managing, configuring and administering the users desktops.
>
> My earlier attempts to get this done has failed!!! I've
> added the desktop support people to a new group
> named "Desktop Support" and then I created a new group
> policy which denies them log on access to the servers OU.
> Since these guys are Domain Admins my policy restriction
> is not working. They can still logon to the servers.
>
> I thought that the deny permission was supposed to take
> priority over the allow permission. Please help as I'm
> being pressured to deliver a solution on this security
> threat.
>
> I passed the Win 2k Server Exam so I'm not at a total loss
> of NTFS permissions. I just don't know what I'm doing
> wrong here. Does this require changing ADSI info, taking
> them out of the Domain Admins group or something else?
>
> My desktop guys need to be administrators on all the
> desktops whenever they logon with their account, but I do
> not want them to be able to perform any account management
> or server administration.
>
> Thanks,
>
> Jason



  #5  
Old 06-03-04, 06:12 PM
Jason
Re: Restrict Desktop Administrators Issue
Thanks for the quick replies I'll let you guys know if it works.

Thank you,

Jason.
 


Popular forums
A+ (A Plus) Windows 2000 Active directory Exchange 2000 information store
Network+ Windows XP Security Exchange 2000 server administration
MCSE .NET Web services SQL Server
Cisco certification ASP .NET SQL 2000 Programming
Windows 2000 Registry .NET XML Viruses


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 12:24 PM.


Powered by vBulletin Version 3.6.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright MCSE braindumps 2003-2006