K
klose
If a regular domain user, installs the 2003 adminpak, they can browse the
ADUC containers.
a) Why is this not locked down to at least a domain administrator or some
other group?
I am aware of the GP that can lock down the various tools, and the
customization of the mmc window, but can not control it from the default
tool within the administrator tools console.
b) After you grant use of the ADUC tool to certain members, they can see
EVERYTHING.
The default permissions on the ADUC objects allows Authenticated Users at
least RO rights on the Builtin, computers, ForeignSecurity Principles...etc
folders.
Can these rights be changed without affecting other system/domain needs?
My goal is to deploy minimal tools to remote office administrators, I have
already used asdi edit and delegation wizard to effect limitations....but
they still see way to much.
ADUC containers.
a) Why is this not locked down to at least a domain administrator or some
other group?
I am aware of the GP that can lock down the various tools, and the
customization of the mmc window, but can not control it from the default
tool within the administrator tools console.
b) After you grant use of the ADUC tool to certain members, they can see
EVERYTHING.
The default permissions on the ADUC objects allows Authenticated Users at
least RO rights on the Builtin, computers, ForeignSecurity Principles...etc
folders.
Can these rights be changed without affecting other system/domain needs?
My goal is to deploy minimal tools to remote office administrators, I have
already used asdi edit and delegation wizard to effect limitations....but
they still see way to much.