Link to home
Start Free TrialLog in
Avatar of Jaime Campos
Jaime CamposFlag for United States of America

asked on

Lock down IT Intern accounts

What is the best way to lock down IT-Intern accounts within active directory? I created a group and added them to group. At the root of AD, I went to security and modified IT-Intern group to only Read-Only, however not sure what else I should do. Is this the best way? Thoughts? Thanks.

nimdatx
Avatar of Joseph Moody
Joseph Moody
Flag of United States of America image

Make a list of actions you want them to do in AD and where these actions should be scoped to. For example, you may want them to have the create computer account permission under a specific OU.

Then use the delegate control wizard to assign these permissions to their group.
What do you mean by IT-intern account, can you explain more. What are you trying to achieve?
To start off with... don't allow them to be administrators of their computers. Other then that they are pretty much like regular employees aren't they? There is no hard and fast rule as far as what you allow and what you don't. Each company is different. You sometimes have to decide and implement on the fly.
ASKER CERTIFIED SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial