Click here to get back home

Allow update of properties without allowing password changes, etc

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Allow update of properties without allowing password changes, etc Dedicated_Dad 02-02-2006
Get Chitika Premium
Posted by Joe Richards [MVP] on February 4, 2006, 3:22 pm
Please log in for more thread options
Wow you really did that the hard and insecure way. Just an FYI, the people who
are in that group very likely have enough permissions now to escalate themselves
to domain or enterprise admins.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



Dedicated_Dad wrote:
> Figured I'd post the solution in case it may help someone else...
>
> First I added the "assistant" to the "Account Operators" group. This gave
> more rights than necessary, so we needed to 'deny" the extra stuff.
>
> Drilling into the Advanced security properties (make sure you turn on "View
> Advanced Features"!) and clicking "Add", after adding the account (or group)
> in question, change the "Apply Onto" dropdown to "User Objects" and add the
> "Deny" permission for:
>
> Change Password
> Modify Permissions
> Receive As
> Reset Password
> Send As
>
> Write Group Membership
> Write PwdLastSet (80%)
> Write x500uniqueidentifier (99)
> Write userpkcs12 (95)
> Write usercertificate
> write security protocol (90)
> write msdrm-identity certificate
> write attributecertificateattribute
> write attirbutecertificate
> write accountexpires
>
> This allows them to edit the address, phone, organization, etc. without
> allowing password, group, or other "security-related" changes.
>
> Hope this helps someone...
>
> DD
>

Similar ThreadsPosted
Files Associated With Client Component of TCP/IP Properties October 17, 2006, 1:10 am
How to search the properties of all the DCOM objects on a machine at once December 18, 2005, 7:17 pm
Allowing applets to create and write to a file June 8, 2005, 7:50 am
Allowing a local account to log on as batch/service? July 18, 2005, 2:15 am
Allowing Users to Increase Scheduling Priority November 15, 2005, 10:35 pm
Allowing SNMP traffic through "Windows Firewall" on WIN2K3 SP1 October 4, 2005, 7:52 am
IPSec - allowing access to specific ports on specifc IP addresses March 11, 2008, 4:27 pm
Discrepancy between MS Update and MSBSA August 23, 2005, 12:30 pm
what to use for internal update infrastructure? July 18, 2006, 4:06 pm
Base Smart Card CSP Update December 7, 2005, 3:12 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap