Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Notices

Windows

Windows forum sponsored by

For all of your Windows problems

Go Back   EduGeek.net Forums > Technical > Windows
Reply
 
LinkBack Thread Tools Search Thread Language
Sponsored Links
Old 31-10-2006, 10:59 AM   #1
 
browolf's Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 565
Thanks: 5
Thanked 12 Times in 7 Posts
Rep Power: 11 browolf will become famous soon enough
Default admins and domain admins

my NM is having a thing about passwords and security. All admins are being demoted to domain admins, well thats just me and him. But I can add myself to the administrators security group at any time. how's that secure?
  Reply With Quote
Old 31-10-2006, 11:05 AM   #2
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,887
uk uk lancashire
Thanks: 42
Thanked 223 Times in 203 Posts
Blog Entries: 1
Rep Power: 66 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default Re: admins and domain admins

It isn't. Your NM might wish to research and test policies prior to implementation in future.
  Reply With Quote
Old 31-10-2006, 11:34 AM   #3
 
browolf's Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 565
Thanks: 5
Thanked 12 Times in 7 Posts
Rep Power: 11 browolf will become famous soon enough
Default Re: admins and domain admins

we was just testing it on our inset day.
  Reply With Quote
Old 31-10-2006, 11:50 AM   #4
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,887
uk uk lancashire
Thanks: 42
Thanked 223 Times in 203 Posts
Blog Entries: 1
Rep Power: 66 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default Re: admins and domain admins

Well, what is the 'problem' he's trying to solve? Maybe we could offer an alternative technical/policy solution?
  Reply With Quote
Old 31-10-2006, 11:55 AM   #5
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 4,133
uk
Thanks: 30
Thanked 93 Times in 92 Posts
Rep Power: 32 plexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of light
Default Re: admins and domain admins

I presume you all use normal accounts for your every day to day operations and only use admin accounts when needed?

Ben
  Reply With Quote
Old 31-10-2006, 12:11 PM   #6
 
IanB's Avatar
 
Join Date: Oct 2005
Location: West London
Posts: 52
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 IanB is an unknown quantity at this point
Default Re: admins and domain admins

:? IMHO the problem exists between the network managers chair and keyboard if he wishes to 'demote' you to the highest level of access in a domain- Domain Admins group is automatically a member of every local Administrators group on every computer, including the DC...
  Reply With Quote
Old 31-10-2006, 12:40 PM   #7
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 4,133
uk
Thanks: 30
Thanked 93 Times in 92 Posts
Rep Power: 32 plexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of light
Default Re: admins and domain admins

Thats where I got a bit confused as to what he was trying to say actually I don't understand what they are supposedly being demoted from Enterprise Admins?

Or from local admins to domain admins dunno didn't actually make sense.

Ben
  Reply With Quote
Old 31-10-2006, 12:45 PM   #8
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,887
uk uk lancashire
Thanks: 42
Thanked 223 Times in 203 Posts
Blog Entries: 1
Rep Power: 66 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default Re: admins and domain admins

Emterprise Admins can Admin all domains in a Forest. Domain Admins can only Admin a single domain in a forest. This is entirely irrelevent for most schools as most people run a single domain in a single forest on one site. So Enterprise Admins and Domain Admins are functionally equivelent.
  Reply With Quote
Old 31-10-2006, 02:41 PM   #9
 
browolf's Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 565
Thanks: 5
Thanked 12 Times in 7 Posts
Rep Power: 11 browolf will become famous soon enough
Default Re: admins and domain admins

Quote:
Originally Posted by plexer
I presume you all use normal accounts for your every day to day operations and only use admin accounts when needed?

Ben
that is the intended idea. pretty much everything i do requires domain admin rights, dunno about administrator

Quote:
Originally Posted by Geoff
Emterprise Admins can Admin all domains in a Forest. Domain Admins can only Admin a single domain in a forest. This is entirely irrelevent for most schools as most people run a single domain in a single forest on one site. So Enterprise Admins and Domain Admins are functionally equivelent.
i didnt realise that. whats the difference between domain admins and the administrators security group then?
  Reply With Quote
Old 31-10-2006, 02:43 PM   #10
 
browolf's Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 565
Thanks: 5
Thanked 12 Times in 7 Posts
Rep Power: 11 browolf will become famous soon enough
Default Re: admins and domain admins

Quote:
Originally Posted by Geoff
Emterprise Admins can Admin all domains in a Forest. Domain Admins can only Admin a single domain in a forest. This is entirely irrelevent for most schools as most people run a single domain in a single forest on one site. So Enterprise Admins and Domain Admins are functionally equivelent.
i didnt realise that. whats the difference between domain admins and the administrators security group then?
  Reply With Quote
Old 31-10-2006, 03:05 PM   #11
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,887
uk uk lancashire
Thanks: 42
Thanked 223 Times in 203 Posts
Blog Entries: 1
Rep Power: 66 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default Re: admins and domain admins

Quote:
whats the difference between domain admins and the administrators security group then
There's three 'Administrators' security groups. Do you mean Enterprise Admins, Domain Admins, or Administrators? It also depends on context. Do you mean on a member server/client or a Domain controller?
  Reply With Quote
Old 31-10-2006, 03:21 PM   #12
 
browolf's Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 565
Thanks: 5
Thanked 12 Times in 7 Posts
Rep Power: 11 browolf will become famous soon enough
Default Re: admins and domain admins

actually thats the least of my worries, i was just to make sense of policies being implemented over my head

trying to enable "password must meet complexity requirements" in group policy but its not working. not sure where im going wrong.

will try to explain what i've done
created a test OU with the attached normal staff policy
added another test policy which will contain the alterations im trying
created a test user in the test OU

enabled password complexity and minimum password length
in computer config/windows settings/security settings/account policies/password policy and loopback to force it to apply the computer settings to the user account

should work, but lets me put anything as the password.
  Reply With Quote
Old 31-10-2006, 03:27 PM   #13
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,887
uk uk lancashire
Thanks: 42
Thanked 223 Times in 203 Posts
Blog Entries: 1
Rep Power: 66 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default Re: admins and domain admins

Password complexity requirements have to be set in a GPO that applies to Domain controllers as its DC's that enforce the complexity requirements not the client PC/User. Typically this is done in the 'Default Domain Controller' GPO.
  Reply With Quote
Old 31-10-2006, 03:30 PM   #14
 
browolf's Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 565
Thanks: 5
Thanked 12 Times in 7 Posts
Rep Power: 11 browolf will become famous soon enough
Default Re: admins and domain admins

ohhhhh surely that means it either applies to everyone or no-one...
  Reply With Quote
Old 31-10-2006, 03:36 PM   #15
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 4,133
uk
Thanks: 30
Thanked 93 Times in 92 Posts
Rep Power: 32 plexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of light
Default Re: admins and domain admins

Absolutely password policies do exactly that.

You can only have one in the domain.

Ben
  Reply With Quote
Reply

Register now for FREE and post messages!


Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Birthday:      
Image Verification
  I agree to forum rules 

Similar Threads
Thread Thread Starter Forum Replies Last Post
Allowing USB memory sticks for non admins... Don't hit me! MrLudwig Windows 16 03-12-2007 09:08 PM
USB devices for non-admins eejit Windows 46 15-11-2007 04:50 PM
Know your UNIX admins ITWombat Jokes/Interweb Things 0 09-04-2007 04:36 PM
Local admins and Mandatory Profiles Bobo Windows 21 02-04-2007 03:02 PM
Can I stop local admins accessing C$ default shares? sidewinder Windows 6 22-02-2007 08:36 PM



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT +1. The time now is 09:35 PM.
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright EduGeek.net