Click here to get back home

How to Create Restricted User at the Win2K3 DOMAIN Controller

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
How to Create Restricted User at the Win2K3 DOMAIN Controller Barun Kumar Tiw 08-14-2007
Posted by Barun Kumar Tiw on August 14, 2007, 2:00 am
Please log in for more thread options
Hello all,
I am a new guy and its my first job as a System Manager of a Windows 2003
Server Domain with Windows XP Clients. I want to create a Secondary Logon
(User) at the Windows 2003 Domain Controler (apart from Domain
Administrator)who should have ONLY below mentioned Rights:
PART: A
1. Can Logon at the Domain Controler / Server and from any of the Client
Systems.
2. Should only be able to Restart and Shut Down the Server.
3. Should not be able to Start any Application, specialy SQL Server
Enterprise
Manager / Query Analyzer at any cost at the Server.
4. Should not be able to Install any Program at the Server or at the Clients.

PART: B
1. Apart from the above rights (with a little change in point no 3 above) is
it posible
to allow this user to start SQL Enterprise Manager or Query Analyser for
Backing
up Databases only. That is He should not be able to Create, Drop, Modify,
Insert
or Update Databases.

Any help is highly appreciated. With regards,

Barun Kumar Tiwari
New Delhi, India.


Posted by Dana Epp [Security MVP] on August 24, 2007, 1:21 am
Please log in for more thread options
Hey there!

You are asking a lot of different questions. However, they all root back to
controlling access policies.

As an example, you could create a Security Group called "ShutdownGroup" and
create a GPO and link it to any OU containing the server(s) in question.
Then you can specify the "Shutdown the system" policy which is located in
"User Rights Assignment" for the local Policy to give this group the
privileges needed. Of course you will need to assign the user(s) you want to
have these privileges to that group.

A question I would like to pose is why you would want a person that you
cannot trust to run code to have interactive logon privileges to your domain
controller and/or SQL server in the first place. You would be far better off
using the security permissions built into SQL to allow your user to remotely
connect to the SQL server and do whatever queries and maintenance that you
want. There are built in stored procedures in SQL like sp_grantlogin and
sp_grantdbaccess that would allow you to manage login for users through
Windows Authentication. You can use the built in roles and permissions to
then provide fine granted access control to which ever databases you want
them to backup. Of course, you would be better served to have regular
automated backups so a user wouldn't even need these privileges in the first
place.

You may have a good reason to require a user to have such privilege.
However, I would recommend that you consider using least privilege here and
find ways to apply the built in technical safeguards in AD and SQL to
restrict the privileges to the lowest set possible. There really is no
reason they need interactive logon rights for a lot of this.

---
Regards,
Dana Epp [Security MVP]
http://silverstr.ufies.org/blog/


> Hello all,
> I am a new guy and its my first job as a System Manager of a Windows 2003
> Server Domain with Windows XP Clients. I want to create a Secondary Logon
> (User) at the Windows 2003 Domain Controler (apart from Domain
> Administrator)who should have ONLY below mentioned Rights:
> PART: A
> 1. Can Logon at the Domain Controler / Server and from any of the Client
> Systems.
> 2. Should only be able to Restart and Shut Down the Server.
> 3. Should not be able to Start any Application, specialy SQL Server
> Enterprise
> Manager / Query Analyzer at any cost at the Server.
> 4. Should not be able to Install any Program at the Server or at the
> Clients.
>
> PART: B
> 1. Apart from the above rights (with a little change in point no 3 above)
> is
> it posible
> to allow this user to start SQL Enterprise Manager or Query Analyser for
> Backing
> up Databases only. That is He should not be able to Create, Drop,
> Modify,
> Insert
> or Update Databases.
>
> Any help is highly appreciated. With regards,
>
> Barun Kumar Tiwari
> New Delhi, India.
>


Similar ThreadsPosted
Create restricted user account, 2003 server AD domain November 10, 2005, 10:39 pm
Normal user logging onto Win2003 Domain Controller? December 3, 2007, 7:03 am
Create User and Auto Assign to Domain Security Group January 31, 2007, 12:27 pm
Restricted User Group November 5, 2005, 3:37 pm
StartDoc fails on W2003 SP1 on a restricted user May 24, 2006, 8:48 am
How to create a user with access to one server only. April 30, 2007, 6:48 am
Domain Controller That Service a DMZ October 29, 2005, 9:58 pm
Domain Controller Security January 13, 2006, 4:43 pm
Domain Controller Security Policy August 12, 2005, 4:31 pm
Want to make an Admin for only one Domain Controller April 7, 2006, 4:42 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap