maalox Posted March 19, 2015 Posted March 19, 2015 (edited) Hello everyone, Our school has a new class in which the students will have the task of doing some help desk work and running tickets. I want to create an AD group with limited admin resources. These select students will need full access to machines and to a few shares I specify. But what I am looking for are a few examples I can use and then create my own. For instance. We have a summer help account that I use to allow the students full admin rights to the machines. And low and behold I have one student who decided to log in with that account to change DNS settings to allow him to bypass opendns. Is there a way to create the group with limited admin rights? AS I am writing this I realize I can use group policy. But is that the only way? Edited March 19, 2015 by maalox
Blue_Cookeh Posted March 19, 2015 Posted March 19, 2015 Give them admin rights and then lock down as appropriate using group policy. You can easily limit the Control Panel items they're allowed to etc. Might be worth creating a custom MMC for them also...
mrbios Posted March 19, 2015 Posted March 19, 2015 What kind of access do they need? what tasks do they need to achieve? what administrative programs (such as AD resetting password etc.) do they require? You could create a domain group, assign them to it, then use GPP to assign that group to the local admin of your PCs, that way local admin is easy to add and remove using one group. Then just assign rights based on what they require in terms of domain access using security rules and access delegation....certainly wouldn't recommending making them domain admins though, that'd be potential suicide. I used to have a 6th former with AD access, he was able to see the student OU only and reset their passwords, and that was about it...albeit i forget exactly how i did that, but im sure it was as above, delegation + security tab.
Ric_ Posted March 19, 2015 Posted March 19, 2015 If you are going to give students a level of responsibility, you should define what that is (e.g. ability to reset passwords or maybe log on as a local admin todo some hardware-related task). You should still have your network-level security in place though (for the example of your DNS thing... why would you allow access to anything other than your own internal DNS?). If they then abuse the responsibility, they need to be disciplined - if a kid helping to answer the phones in reception walked in and started answering the phones when they weren't supposed to, you'd discipline that, yeah? For the above to work... each little helper will need their own account and you need to audit EVERYTHING. Likewise, you should have that for any administrative user, just to cover your own back.
maalox Posted March 24, 2015 Author Posted March 24, 2015 Thank you everyone for you helpful insight. Its much appreciated.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now