Solved

Restrict Domain Admins From Changing Built-In Administrator Account Password

Posted on 2014-01-02
7
1,181 Views
Last Modified: 2014-03-03
Hello Everyone,

Our company does IT Outsourcing, as such we have many different businesses, users, and servers to look after on a day-to-day basis.  The problem that I am currently faced with is that as we grow we are requiring more techs to handle the workload, which is good but requires me to rethink our security policies, in that, if someone has to be let go, or quits, then instead of having a few passwords to change like in your typical in house IT department, we have many passwords to change, across, many servers, many clients, and many devices.  I've already worked out how to take care of most of the issues, such as network scanners that have the admin password for authentication to shares, but the main one I'm faced with right now is how do I make it so that my techs have the access they need to do work on the servers and preform installations and other things on local workstations, but cannot change the built-in administrator password.  This way if one of them is let go or quits, all I have to do is go through each server and change the tech admin account password since that's the only admin password they'll be privy to.  Any help is greatly appreciated, thanks.
0
Comment
Question by:ctagle
  • 4
  • 3
7 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39751446
What I would recommend is creating/using "service accounts" with long complex passwords for specific devices like scanners, services for specific applicaitons etc. This way you do not have to go around and reset those passwords.

As for Local Admin accounts you can use Group Policy Perferences to accomplish this and reset local admin accounts.

You can find the details at the following link.
http://social.technet.microsoft.com/Forums/windowsserver/en-US/b1e94909-bb0b-4e10-83a0-cd7812dfe073/change-local-administrator-password-thru-gpo?forum=winserverGP

Will.
0
 

Author Comment

by:ctagle
ID: 39752469
Thank you for the reply.  That should work nicely for simplifying the process of changing the passwords, but I didn't see anything about restricting domain admin accounts from being able to change the password on the built-in admin account or on an account I specify.  I can restrict the gpo I think and not tell them the password for the built-in admin account, but then they can just go into AD and change the password right?  Or am I missing something?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39752527
If the users need to be domain admins then you cannot stop them from changing the password. If they do not require domain admin rights then you can use delegation of control and restrict what your users can do. You can always audit password changes from the security logs on the domain controllers.

You might also be able to use the deny permission on the account for password reset (I would try this in a test environment first).

Will.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:ctagle
ID: 39752589
ah ok, is there a way  that I can give them access to the admin functions, such as AD, exchange, backups, share management, ability to install programs and updates on workstations (authenticating through UAC or logging on as the domain user they are assigned), etc... without making them a domain admin?  If so then I think I could possibly figure something out, I haven't had much success in the past though with domain accounts having admin priveleges on workstations unless they are domain admins.
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 39752631
You can use role based access control for Exchange and you can use delegation of control to set specific admin requirements. Below is a link which outlines some of the main functions you can delegate with delegation of control wizard.

http://technet.microsoft.com/en-us/library/dd145442.aspx

Will.
0
 

Author Comment

by:ctagle
ID: 39794547
Thanks for the replies, I'll be trying the delegation of control wizards once my mock up server comes in.  Should hopefully be this week, i'll let you know how it turns out.
0
 

Author Closing Comment

by:ctagle
ID: 39900912
Didn't really have much a chance to try this stuff out, and there's no sense in leaving a question open, I will look into this more in depth now that I have a vsphere host in place that I can setup mock up vms on.  Thank you for the information.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question