Click here to get back home

Block server reboots?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Block server reboots? Transam388 04-04-2007
Posted by Transam388 on April 4, 2007, 2:22 pm
Please log in for more thread options
We have a 2003 Enterprise A/P cluster with Exchange 2003 in the cluster. We
have had a fair number of instances where a different office pushes patches
via SMA and or applies them manually and then reboot the system in the middle
of our work day. Obviously this gets me looking like an idiot and it appears
as though we are in a no win scenario getting them to stop doing this. What
the question is...is there a way to set a 2003 server to not reboot unless
done with an authorized account or password on the systems themselves? This
meaning that even if who is logged in is a domain admin, if they try to shut
down the system it would either not allow them to or it would prompt for the
shutdown password before doing a reboot. Thanks!!

Posted by Danny Sanders on April 4, 2007, 5:52 pm
Please log in for more thread options
None that I'm aware of.

If you are a domain admin, and the people restarting the server are domain
admins, what ever you do to lock down the server from rebooting, they as
domain admins can undo.

You might have to come at this from the standpoint of service interruption.

We have several domain admins here, but we have strict change controls, all
patches that require a reboot must be scheduled and done "after hours",
reboots, unless under a circumstance where the service is already down, are
not allowed. If something has to be done to a server on the network that
does not require a reboot, we have to get approval from a manager or two
other system admins or it can't be done.

We have a huge network serving over 8,000 people all over the world. This
works for us, might be over kill for smaller networks but your change
controls can be adjusted for your environment.

At least you may be able to get them to give you a warning so you can send
out an email.


hth
DDS


> We have a 2003 Enterprise A/P cluster with Exchange 2003 in the cluster.
> We
> have had a fair number of instances where a different office pushes
> patches
> via SMA and or applies them manually and then reboot the system in the
> middle
> of our work day. Obviously this gets me looking like an idiot and it
> appears
> as though we are in a no win scenario getting them to stop doing this.
> What
> the question is...is there a way to set a 2003 server to not reboot unless
> done with an authorized account or password on the systems themselves?
> This
> meaning that even if who is logged in is a domain admin, if they try to
> shut
> down the system it would either not allow them to or it would prompt for
> the
> shutdown password before doing a reboot. Thanks!!



Similar ThreadsPosted
W2K - Block USB through GPO ? July 12, 2005, 10:43 am
block IM August 19, 2005, 11:16 am
Block MSN Messenger August 18, 2005, 5:03 pm
Block Toolbars April 26, 2006, 1:22 pm
How to Block UltraSurf? July 17, 2008, 9:50 am
Block file copy October 4, 2005, 10:10 am
ipsec to block ip range November 22, 2005, 12:12 pm
Block Remote Control July 6, 2007, 1:18 pm
Block Unauthorized Computer October 31, 2007, 11:06 am
[?]block entire network ranges October 14, 2005, 4:02 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap