|
Where I come
from, we have this phrase that sums up Rick’s message real short and
sweet “damn domain admins”. It’s all political. --Brian Thanks. --Brian Desmond Payton on the
web! www.wpcp.org v - 773.534.0034 x135 f - 773.534.8101 c -
312.731.3132 From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rick Kingslan joe – Great answer in a perfect world.
Great answer in the joe-run world. I’d like to do the same, but
it’s kind of funny that the guys I can’t really trust, the company
still employs because I can’t get evidence that is going to get them
fired to the degree in which HR is not going to spend the next 30 years in a
court room over false termination. If Rick Neuheisal can get $4.7 Million
for being fired as a coach because he violated NCAA rules, I’m sure that
the morons that I have to employ can make our life tough by being stupid on our
network. I can’t move them off to other
functions. Why? If I can’t fire them, I can’t replace
them. Management (upper) is kind of funny that way in the world that I
live in. The best that I can hope to do is to remove rights to the point
that if they piss themselves, it’s just their own mess – no one
elses. I suspect Mr. Lunsford is much more like
me. He’s in an environment where he has to employ people that
aren’t as good as we’d like them to be. Or, maybe even as
trustworthy as we’d like. So, that means that we:
Usually, the advice that “You
can’t do that” isn’t realistic. -rtk From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe You can't. Period. Solution: Don't give these people who are
untrustworthy administrator or any native group access and don't let them log
on interactively to your DCs or allow them to modify the file systems nor
registry nor services. Summary: You can't. Period. joe From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of [EMAIL PROTECTED]
|
- RE: [ActiveDir] Problem: Limit Domain Admins and... deji
- RE: [ActiveDir] Problem: Limit Domain Admin... Rick Kingslan
- RE: [ActiveDir] Problem: Limit Domain Admin... Brian Desmond
- RE: [ActiveDir] Problem: Limit Domain Admin... Renouf, Phil
- RE: [ActiveDir] Problem: Limit Domain Admin... Gil Kirkpatrick
- RE: [ActiveDir] Problem: Limit Domain Admin... Ruston, Neil
- RE: [ActiveDir] Problem: Limit Domain Admin... Myrick, Todd (NIH/CC/DNA)
- RE: [ActiveDir] Problem: Limit Domain Admin... Gil Kirkpatrick
- RE: [ActiveDir] Problem: Limit Domain Admin... Gil Kirkpatrick
- RE: [ActiveDir] Problem: Limit Domain Admin... Isenhour, Joseph
