Solved

Locking down an OU in AD Windows 2008 Server

Posted on 2010-08-26
9
741 Views
Last Modified: 2012-05-10
Hello,

I am managing an AD Windows 2008 Forest with multiple domains and we've just acquired another company. Because of compliancy and security crap from auditors I have to come up with a way to integrate this new company into my Forest. Management mentioned that they can sell the idea to the security auditors of creating an OU and putting the users of the different company in there and locking that OU down so that they are not able to do anything at the root of the Forest.

Tacobell2000
0
Comment
Question by:Tacobell2000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 3
9 Comments
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 33537418
What security provisions do you want to put in? You apply Group Policies to stop them from doing functions but it depends on what you want to restrict.
0
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33537512
A forrest, domain or OU can in theory operate as a security boundry but domain users won't be able to do much unless they are granted permissions to do so anyways but as darius said, some more info is required. Of course if you granted or left default permissions for domain users or authenticated users to recoursces you have to undo that to be able to restrict things.

0
 

Author Comment

by:Tacobell2000
ID: 33537628
ok....i just want these users (integrated company) to have their own OU and to be able to manage their OU only. I do not want them to modify anything else just their OU.
Does this make sense?

Tacobell2000
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 24

Accepted Solution

by:
Mike Thomas earned 250 total points
ID: 33537665
That's fine that can be done, stick them all in an OU, add any admins into a group you create called say "other company admins" then when selecting advanced view in AD U&C select the security tab on that OU, then properties and give "other company admns" full contro,l they will in effect be domain admin but just for that group and nothing else.






0
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33537676
You could alos delegate to them by right clicking the OU and slecting that option and running thruough the wizard but that might be too restrictive for admins AND IMO causes too much bad feeling and mistrust without reason.




0
 
LVL 59

Assisted Solution

by:Darius Ghassem
Darius Ghassem earned 250 total points
ID: 33537733
That does make sense you can use delegation with AD to give them access to their own OU and to manage the OU.

http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html
0
 

Author Comment

by:Tacobell2000
ID: 33543382
Just curious....how about creating a child domain and let them have whatever control they want on the newly created domain and restricting them at the forest level.....will that work?

Tacobell2000
0
 

Author Comment

by:Tacobell2000
ID: 33543483
Also....how about creating a new forest and creating trusts between them....that would probably be the way to go....since domains are not security boundaries.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 33543504
You can create a  new tree within your current forest if you want to do that.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A procedure for exporting installed hotfix details of remote computers using powershell
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question