Solved

Best Method to Restrict Admins and Audit Active Directory

Posted on 2013-12-10
5
367 Views
Last Modified: 2014-01-06
Hello Experts!

I currently run a single domain environment across multiple sites. I'm looking to hire some new technicians, but don't want to give them the "keys to the kingdom."

What is the best method to restrict admin accounts? Do I have to go through and create security groups, etc.?

Also, what are your recommendations on auditing changes made across the domain?


Thank you for your time!
J
0
Comment
Question by:jmichaelpalermo4
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39708921
Best method is to first talk to them and your team and see what tasks they will need to perform?   Then you start your delegation plan from there.

Yes you can create groups and delegate permissions.   You an also use some of the builtin groups (account operators for example).

Do you have any third party auditing tools or using native tools?

Thanks

Mike
0
 
LVL 9

Accepted Solution

by:
VirastaR earned 250 total points
ID: 39708958
Hi,

You can simply achieve it my using "Delegation Control" wizard using ADUC and you get more granular you want and user can do just what you define nothing less or more, this applies even to auditing the AD.

Using GUI Tools:

Active Directory rights delegation – overview
&
Using the Delegation of Control Wizard to Assign Permissions in Server 2008

Using Powershell:

Checking Permission/Delegation of an OU/Domain-Quest PowerShell

Hope that helps :)
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39709062
As mentioned above Delegation of Control is a huge part to lock down what your helpdesk/systems admins can do.

I would recommend creating new Security Groups giving them a meaningful name for Each Job function i.e.
AD_Password_Admin (this account can reset and unlock users accounts in AD) AD_User_Admin (this group can modify user attributes and create new Users) AD_Computer_Admin (this group can modify computer attributes/objects) etc...

From there you will have a clear indication of what the users specific account has access to do just by looking at the Membership Tab.

For Auditing ADAudit Plus is the software i recommend for auditing changes being done in your AD environment. Not free but not expensive. They have a fully featured free trail.

AD Audit Plus - http://www.manageengine.com/products/active-directory-audit/

Will.
0
 
LVL 3

Expert Comment

by:Detlef001
ID: 39711468
Hey, wouldn't log on to a user's workstation with Domain Admin credentials of any kind. You should use Group Policy restricted groups to gin up another administrative group for workstation use. Using a member of Domain Admins local to a workstation could hand the keys to your entire network to everyone in the world.

As for what you're asking for, limited control of cmd.exe, I can't off the top of my head think of a way to do that.

If you're already making your users local admins, what problem are you trying to solve or avoid?

Moreover you can go for an third party application also. Please click on the given link for the same.

Thanks.
0
 
LVL 3

Author Closing Comment

by:jmichaelpalermo4
ID: 39759884
Thank you!
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question