Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus batch bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard mouse network printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Need suggestions - Setting up Secondary LUA Domain Admin

Reply  
Thread Tools
JCBNAZ's Avatar
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2007
Location: Phoenix, AZ
Experience: Network Administrator
29-Nov-2007, 02:56 PM #1
Question Need suggestions - Setting up Secondary LUA Domain Admin
In our organization (Environment is Win 2k3 Server Ent. R2 x32, Win XP Pro x32) , the CIO has decided to tighten up our policy & procedures. We have a Help Desk that has a Tier 1, 2 & 3 level of support. Currently, the tier 2 & 3 uses the Builtin Domain Admin account (at the workstation level) for resolving issues, client configuration and troubleshooting. We want to create a secondary 'Junior Domain Administrator' account for tier 2 & 3 to use @ the workstations. This way it keeps prying eyes from the God account PW and allows us to keep the God account @ the Server level only.

Rather than adding individual support personnel to a Security Group in AD for this purpose, we want to set up one limited 'blanket' account IT personnel to use that has principle of Least Priviledge to User Accounts. Using the 'Run As' really doesn't fit our need either.

We only want this 'secondary account' to have the following capabilities when logging into the workstation level:

1. Add/Remove Programs
2. Change a User's Profile level (Power user, standard user, etc)
3. Configure / Change IP & Network settings @ the workstation
4. Attach / Detach client from Domain

What would the best configuration be for this account? Add this account to Administrator SG, then tighten it up via GPO? If GPO is the route, what is the best settings to use? My CIO asked if it would be easier to set up a local account on each PC and just use that. I disagree as 300+ clients would be a PITA and we should be able to restrict with GPO. I am not that knowledgable to get so granular with GPO's.

Are many of you using a secondary account for user support @ the workstation? You help and real world solutions would be appreciated!

Thanks!
John

P.S - Any needed clarification on this 'description' - just ask!
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 01:54 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.