Solved

Block Active Directory Interference

Posted on 2006-11-16
3
239 Views
Last Modified: 2012-06-27
Hello Experts,

This is going to sound super paranoid, but put yourself in my shoes before you judge...

Here's my dilemma. I work for a school (school A) that sells some of my time to another school (school B). School B uses active directory and school A does not. School B requires that I use outlook for email, which in turn requires me to be on their domain. Since I am a competent tech administrator, I want to avoid active directory interfering with anything on my computer: i.e. I don't want them to push updates down to me, don't want them to have access to my files / registry / etc... loss of control = sad tech guy

I have removed Domain Admins from my local administrator group and anything else domainish from other groups so I think that should take care of most of it, but what I need to know is can they still do anything just because I am a member of the domain?
If so, what ports / services do I need to block to ensure that I don't have to worry about any funny business like my computer restarting in the middle of an unsaved page of code because they are sending down updates?

Also, how do I remove any group policies that they have pushed down and prevent this from happening in the future.

Thanks in advance,

-jkorz
0
Comment
Question by:jkorz
  • 2
3 Comments
 
LVL 9

Expert Comment

by:trenes
ID: 17958871
Hi jkorz,
> School B requires that I use outlook for email,
Can't they use OWA? So you wont have to login into their domain.

But in my opinion, If you dont trust them you should not work for them.

I hope somebody has any tips for you.

Cheers!
regards,

Trenes
0
 
LVL 8

Author Comment

by:jkorz
ID: 17959633
I could use OWA, but I would rather use the client.

It's not that I don't trust them per-se, they have a contracted network admin who doesn't spend much time here and relies heavily on the centralized management that AD provides for updates, security, etc... (things that normal users don't worry about, but I take care of). I want to do what I can (as opposed to relying on others) to avoid any more complications.
0
 
LVL 9

Accepted Solution

by:
trenes earned 500 total points
ID: 17959884
Try asking the admin to place you in an "admin" OU, that is not linked to any gpo.
That should fix things you worry about.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question