There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot bsod computer connection cpu crash css dell desktop dma driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware monitor motherboard network networking outlook outlook 2003 outlook 2007 outlook express pio problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
General Security
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > General Security >
Need suggestions - Setting up Secondary LUA Domain Admin


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
JCBNAZ's Avatar
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2007
Location: Phoenix, AZ
Experience: Network Administrator
29-Nov-2007, 01:56 PM #1
Question Need suggestions - Setting up Secondary LUA Domain Admin
In our organization (Environment is Win 2k3 Server Ent. R2 x32, Win XP Pro x32) , the CIO has decided to tighten up our policy & procedures. We have a Help Desk that has a Tier 1, 2 & 3 level of support. Currently, the tier 2 & 3 uses the Builtin Domain Admin account (at the workstation level) for resolving issues, client configuration and troubleshooting. We want to create a secondary 'Junior Domain Administrator' account for tier 2 & 3 to use @ the workstations. This way it keeps prying eyes from the God account PW and allows us to keep the God account @ the Server level only.

Rather than adding individual support personnel to a Security Group in AD for this purpose, we want to set up one limited 'blanket' account IT personnel to use that has principle of Least Priviledge to User Accounts. Using the 'Run As' really doesn't fit our need either.

We only want this 'secondary account' to have the following capabilities when logging into the workstation level:

1. Add/Remove Programs
2. Change a User's Profile level (Power user, standard user, etc)
3. Configure / Change IP & Network settings @ the workstation
4. Attach / Detach client from Domain

What would the best configuration be for this account? Add this account to Administrator SG, then tighten it up via GPO? If GPO is the route, what is the best settings to use? My CIO asked if it would be easier to set up a local account on each PC and just use that. I disagree as 300+ clients would be a PITA and we should be able to restrict with GPO. I am not that knowledgable to get so granular with GPO's.

Are many of you using a secondary account for user support @ the workstation? You help and real world solutions would be appreciated!

Thanks!
John

P.S - Any needed clarification on this 'description' - just ask!
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 02:47 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.