Solved

Best Method to Restrict Admins and Audit Active Directory

Posted on 2013-12-10
5
353 Views
Last Modified: 2014-01-06
Hello Experts!

I currently run a single domain environment across multiple sites. I'm looking to hire some new technicians, but don't want to give them the "keys to the kingdom."

What is the best method to restrict admin accounts? Do I have to go through and create security groups, etc.?

Also, what are your recommendations on auditing changes made across the domain?


Thank you for your time!
J
0
Comment
Question by:jmichaelpalermo4
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39708921
Best method is to first talk to them and your team and see what tasks they will need to perform?   Then you start your delegation plan from there.

Yes you can create groups and delegate permissions.   You an also use some of the builtin groups (account operators for example).

Do you have any third party auditing tools or using native tools?

Thanks

Mike
0
 
LVL 9

Accepted Solution

by:
VirastaR earned 250 total points
ID: 39708958
Hi,

You can simply achieve it my using "Delegation Control" wizard using ADUC and you get more granular you want and user can do just what you define nothing less or more, this applies even to auditing the AD.

Using GUI Tools:

Active Directory rights delegation – overview
&
Using the Delegation of Control Wizard to Assign Permissions in Server 2008

Using Powershell:

Checking Permission/Delegation of an OU/Domain-Quest PowerShell

Hope that helps :)
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39709062
As mentioned above Delegation of Control is a huge part to lock down what your helpdesk/systems admins can do.

I would recommend creating new Security Groups giving them a meaningful name for Each Job function i.e.
AD_Password_Admin (this account can reset and unlock users accounts in AD) AD_User_Admin (this group can modify user attributes and create new Users) AD_Computer_Admin (this group can modify computer attributes/objects) etc...

From there you will have a clear indication of what the users specific account has access to do just by looking at the Membership Tab.

For Auditing ADAudit Plus is the software i recommend for auditing changes being done in your AD environment. Not free but not expensive. They have a fully featured free trail.

AD Audit Plus - http://www.manageengine.com/products/active-directory-audit/

Will.
0
 
LVL 3

Expert Comment

by:Detlef001
ID: 39711468
Hey, wouldn't log on to a user's workstation with Domain Admin credentials of any kind. You should use Group Policy restricted groups to gin up another administrative group for workstation use. Using a member of Domain Admins local to a workstation could hand the keys to your entire network to everyone in the world.

As for what you're asking for, limited control of cmd.exe, I can't off the top of my head think of a way to do that.

If you're already making your users local admins, what problem are you trying to solve or avoid?

Moreover you can go for an third party application also. Please click on the given link for the same.

Thanks.
0
 
LVL 3

Author Closing Comment

by:jmichaelpalermo4
ID: 39759884
Thank you!
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Resolve DNS query failed errors for Exchange
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now