Use administrative tools to manage DC

Posted on 2009-02-11
Last Modified: 2012-05-06
I read an article saying "If you have users who need to perform delegated administrative functions such as creating/modifying user accounts, install the administrative tools on their desktops and require them to work from there. Logging onto domain controllers should be restricted to Domain Admins only".

So on a workgroup XP (I didn't join to domain), I installed 2003 SP 2 Administration Tools Pack for x86 editions. The workstation is in the same subnet as DC, but I didn't join it todomain. I just open AD users and computers, type in domain name. surprisingly, I was able to delete user!! why???
Question by:bubuko
    LVL 31

    Expert Comment

    by:Toni Uranjek

    Does password of local administrator on Windows XP match password of domain administrator? How are you logged on Windows XP?


    Author Comment

    the password is same. I logged on xp as local admin. But still, it's unbelievable. This let a non-domain user to do that.
    LVL 31

    Accepted Solution

    This is the point, you are actually not logged to domain controller as non-admin user. When your local credentials match those of domain user, you are authenticated as domain user. Change one pr the other password or user name, and you won't be able to access AD if you don't authenticate again with correct credentials.

    Author Comment

    I see.. thank you! But I think it's not very secure like this.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
    Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
    It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
    Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now