Networking Forums

Networking Forums > Computer Networking > Windows Networking > disallow dom admin login at work-st?

Reply
Thread Tools Display Modes

disallow dom admin login at work-st?

 
 
Michael Giorgio - MS MVP
Guest
Posts: n/a

 
      09-09-2004, 02:49 PM
By default the "domain admin" account is added to the
local "administrator" account on all domain members when
joining the domain. If you want to prevent "domain admin"
accounts from logging locally to workstations then remove
the "domain admin" account from the local "administrator"
account on the local machines.

By default only "domain admins" or domain "administrators"
can logon locally to a DC.
"Hernán Castelo" <(E-Mail Removed)> wrote in message news:
hi
can i disallow
login as admins of domain controller
from the workstations?

that is, admins of DC
only can log in the server .

thanks



 
Reply With Quote
 
 
 
 
=?iso-8859-1?Q?Hern=E1n_Castelo?=
Guest
Posts: n/a

 
      09-09-2004, 02:52 PM
hi
can i disallow
login as admins of domain controller
from the workstations?

that is, admins of DC
only can log in the server .

thanks


--
atte,
Hernán Castelo
SGA - UTN - FRBA

 
Reply With Quote
 
Lanwench [MVP - Exchange]
Guest
Posts: n/a

 
      09-09-2004, 03:06 PM
By default, users can't log in locally or via TS to a server.

Hernán Castelo wrote:
> hi
> can i disallow
> login as admins of domain controller
> from the workstations?
>
> that is, admins of DC
> only can log in the server .
>
> thanks



 
Reply With Quote
 
Steven L Umbach
Guest
Posts: n/a

 
      09-09-2004, 05:51 PM
In AD Users and Computers you can restrict which domain computers a user can logon to in their user account properties. Also you can use the user right for logon locally and deny logon locally to restrict what computers a user can logon to. In the appropriate security policy user rights are located under security settings/local policies/user rights.

Having said that, domain admins are all powerful in the domain and can change any policy or user restriction in the domain so you can not realistically restrict them. I would not make someone a domain admin if I could not trust them. Also many functions in the domain can be delegated to regular users including creating and managing user and computer accounts. --- Steve
"Hernán Castelo" <(E-Mail Removed)> wrote in message news:(E-Mail Removed)...
hi
can i disallow
login as admins of domain controller
from the workstations?

that is, admins of DC
only can log in the server .

thanks


--
atte,
Hernán Castelo
SGA - UTN - FRBA

 
Reply With Quote
 
=?iso-8859-1?Q?Hern=E1n_Castelo?=
Guest
Posts: n/a

 
      09-09-2004, 06:30 PM
thanks everybody

what are the main reasons
for disallow work-st to log as admin of dom ?
what are the risks of allow
dom admin account
log on work-st ?
password or permissions can be hacked?

thanks

--
atte,
Hernán Castelo
SGA - UTN - FRBA

"Hernán Castelo" <(E-Mail Removed)> escribió en el mensaje news:(E-Mail Removed)...
hi
can i disallow
login as admins of domain controller
from the workstations?

that is, admins of DC
only can log in the server .

thanks


--
atte,
Hernán Castelo
SGA - UTN - FRBA

 
Reply With Quote
 
Steven L Umbach
Guest
Posts: n/a

 
      09-09-2004, 07:01 PM
A domain administrator should not be logging onto non secured domain workstations to do work that does not require domain admin credentials, and they should know that. You can create a domain global group to add to the local administrators group on domain computers and that group can be a regular user in the domain. That can be done by using Group Policy and "Restricted Groups" at the Organizational Unit level or by a Group Policy startup script. The main risk is that an unsecured typical domain computer may have a keyboard logger, mini camera, or such installed on/near it by a trojan or malicious user to capture users passwords. What I mean by unsecured domain computer is a computer that is not in a locked office or otherwise secured to prevent only authorized users to have physical access to it.

http://support.microsoft.com/default...;EN-US;Q320065 -- note this will remove any current users/groups in the local administrators group other than the built in administrator.
"Hernán Castelo" <(E-Mail Removed)> wrote in message news:(E-Mail Removed)...
thanks everybody

what are the main reasons
for disallow work-st to log as admin of dom ?
what are the risks of allow
dom admin account
log on work-st ?
password or permissions can be hacked?

thanks

--
atte,
Hernán Castelo
SGA - UTN - FRBA

"Hernán Castelo" <(E-Mail Removed)> escribió en el mensaje news:(E-Mail Removed)...
hi
can i disallow
login as admins of domain controller
from the workstations?

that is, admins of DC
only can log in the server .

thanks


--
atte,
Hernán Castelo
SGA - UTN - FRBA

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Q: ypcat, ypwhich etc all work, but still no login emerth Linux Networking 1 11-26-2007 08:39 PM
How to make login script work when using WPA2 in an office? Hari Haran Wireless Networks 5 10-15-2007 10:15 PM
Disallow a wireless network VickyS Wireless Networks 4 09-24-2007 11:58 PM
RDC disallow local user disconnect loosenut Home Networking 0 01-26-2007 12:20 AM
I am interested in Linux Admin, wanted to self learn, what are important things in Admin? GS Linux Networking 12 05-01-2005 01:54 AM



1 2 3 4 5 6 7 8 9 10 11