We help IT Professionals succeed at work.

Use administrative tools to manage DC

bubuko
bubuko asked
on
Medium Priority
241 Views
Last Modified: 2012-05-06
I read an article saying "If you have users who need to perform delegated administrative functions such as creating/modifying user accounts, install the administrative tools on their desktops and require them to work from there. Logging onto domain controllers should be restricted to Domain Admins only".

So on a workgroup XP (I didn't join to domain), I installed 2003 SP 2 Administration Tools Pack for x86 editions. The workstation is in the same subnet as DC, but I didn't join it todomain. I just open AD users and computers, type in domain name. surprisingly, I was able to delete user!! why???
Comment
Watch Question

Toni UranjekConsultant/Trainer

Commented:
Hi!

Does password of local administrator on Windows XP match password of domain administrator? How are you logged on Windows XP?

Toni

Author

Commented:
the password is same. I logged on xp as local admin. But still, it's unbelievable. This let a non-domain user to do that.
Consultant/Trainer
Commented:
This is the point, you are actually not logged to domain controller as non-admin user. When your local credentials match those of domain user, you are authenticated as domain user. Change one pr the other password or user name, and you won't be able to access AD if you don't authenticate again with correct credentials.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts

Author

Commented:
I see.. thank you! But I think it's not very secure like this.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.