?
Solved

Best Method to Restrict Admins and Audit Active Directory

Posted on 2013-12-10
5
Medium Priority
?
373 Views
Last Modified: 2014-01-06
Hello Experts!

I currently run a single domain environment across multiple sites. I'm looking to hire some new technicians, but don't want to give them the "keys to the kingdom."

What is the best method to restrict admin accounts? Do I have to go through and create security groups, etc.?

Also, what are your recommendations on auditing changes made across the domain?


Thank you for your time!
J
0
Comment
Question by:jmichaelpalermo4
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39708921
Best method is to first talk to them and your team and see what tasks they will need to perform?   Then you start your delegation plan from there.

Yes you can create groups and delegate permissions.   You an also use some of the builtin groups (account operators for example).

Do you have any third party auditing tools or using native tools?

Thanks

Mike
0
 
LVL 9

Accepted Solution

by:
VirastaR earned 1000 total points
ID: 39708958
Hi,

You can simply achieve it my using "Delegation Control" wizard using ADUC and you get more granular you want and user can do just what you define nothing less or more, this applies even to auditing the AD.

Using GUI Tools:

Active Directory rights delegation – overview
&
Using the Delegation of Control Wizard to Assign Permissions in Server 2008

Using Powershell:

Checking Permission/Delegation of an OU/Domain-Quest PowerShell

Hope that helps :)
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 1000 total points
ID: 39709062
As mentioned above Delegation of Control is a huge part to lock down what your helpdesk/systems admins can do.

I would recommend creating new Security Groups giving them a meaningful name for Each Job function i.e.
AD_Password_Admin (this account can reset and unlock users accounts in AD) AD_User_Admin (this group can modify user attributes and create new Users) AD_Computer_Admin (this group can modify computer attributes/objects) etc...

From there you will have a clear indication of what the users specific account has access to do just by looking at the Membership Tab.

For Auditing ADAudit Plus is the software i recommend for auditing changes being done in your AD environment. Not free but not expensive. They have a fully featured free trail.

AD Audit Plus - http://www.manageengine.com/products/active-directory-audit/

Will.
0
 
LVL 3

Expert Comment

by:Detlef001
ID: 39711468
Hey, wouldn't log on to a user's workstation with Domain Admin credentials of any kind. You should use Group Policy restricted groups to gin up another administrative group for workstation use. Using a member of Domain Admins local to a workstation could hand the keys to your entire network to everyone in the world.

As for what you're asking for, limited control of cmd.exe, I can't off the top of my head think of a way to do that.

If you're already making your users local admins, what problem are you trying to solve or avoid?

Moreover you can go for an third party application also. Please click on the given link for the same.

Thanks.
0
 
LVL 3

Author Closing Comment

by:jmichaelpalermo4
ID: 39759884
Thank you!
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses
Course of the Month13 days, 1 hour left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question