Solved

REstricting Access to the Server - For administrators

Posted on 2006-11-14
5
226 Views
Last Modified: 2012-03-15
Hi all,

I have a site that has a guy on it that up to now was looking after IT. Due to some difficulties we are taking away his abiliites to work on the server but we still want him to be able to do everything on the pc's such as join domain setup printers install software etc.

So basically I am looking for the best way to stop him logging into the server either at console or remote desktop and also prevent him from managing the server from another machine - but at the same time allow him to manage the pc's without a problem.

Windows 2003 is the OS

Thanks

Michael
0
Comment
Question by:mickinoz2005
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 9

Accepted Solution

by:
trenes earned 84 total points
ID: 17941221
Hi mickinoz2005,

Nice article from Sams.
http://www.samspublishing.com/articles/article.asp?p=98126&seqNum=5&rl=1

I think the best way is to delegate permissions through OU's in your situation. (If no other domains, sites etc)
But read the article and make your own choice.

Cheers!
regards,

Trenes
0
 
LVL 5

Assisted Solution

by:dynamitedotorg
dynamitedotorg earned 83 total points
ID: 17941312
The way I do it is to create a group for workstation admins. This has no particular privileges at all so doesn't allow the user to do anything to AD or a server. However using Group Policy you can automatically make it a member of the local administrators group on each PC thereby giving any member of that group full administrative rights on the PC.

You need to ensure that you only apply that group policy to the machines you want the users to administer, and keep it well away from any that you want to keep them off (e.g. the servers).

The only thing that that won't do is allow him to add machines to the domain. IIRC a normal user can add a certain number of machines anyway, but judicious use of delegation within AD (as outlined above) will sort that out.
0
 
LVL 2

Assisted Solution

by:thelastoftheend
thelastoftheend earned 83 total points
ID: 17942246
I agree with dynamitedotorg - remove this user from any domain admin groups and make him a member of a group which belongs to the local Administrators group on client machines only, applied via Group Policy.

To do this, open your Group Policy and locate the "Restricted Groups" node underneath "Computer Configuration-->Windows Settings-->Security Settings". Right-click and select "Add Group". Type Administrators as the name of the group - this implies the local Administrators group on any computer this is applied to. Click "Add members". Be sure to include "Administrator" and yourdomain\Domain Admins". This policy overwrites any current local Administrators group membership.  Here's a decent description of how to use the policy: http://www.windowsecurity.com/articles/Using-Restricted-Groups.html.

In addition, I would do the following on the server:

1. Browse to "Administrative Tools --> Local Security Settings" (or if its a domain controller, "Administrative Tools-->Domain Controller Security Policy"). Drill down to "Computer Configuration-->Windows Settings-->Security Settings-->Local Policies-->User Rights Assignment".

2. Locate "Deny Logon Locally" and add the user to this right.

3. Locate "Deny Logon through Terminal Services" and add the user to this right.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question