Click here to get back home

Read-only access to AD, 2000, and 2003 server for monitoring?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Read-only access to AD, 2000, and 2003 server for monitoring? SVRSEC 09-07-2007
Posted by SVRSEC on September 7, 2007, 3:20 pm
Please log in for more thread options
I need to know how, if possible, can you set up a user that can have read
access to AD to be able to browse all Administrator level accounts, but not
be able to modify AD in any fashion? The reason for this is to be able to
have our security monitoring area be able to document and research any
Administrator level accounts anywhere in our AD.

I would also like to know if the same is possible for the local accounts for
both 2000 and 2003 AD members and standalone servers?

Posted by Roger Abell [MVP] on September 8, 2007, 2:39 am
Please log in for more thread options
>I need to know how, if possible, can you set up a user that can have read
> access to AD to be able to browse all Administrator level accounts, but
> not
> be able to modify AD in any fashion? The reason for this is to be able to
> have our security monitoring area be able to document and research any
> Administrator level accounts anywhere in our AD.
>

If measures have not been taken to move your forest/domains away from
the as-installed settings, then any account in the forest can do that (well,
I guess it depends on what "able to browse all Administrator level accounts"
intends to mean. If it means list out accounts in the groups, then that
already
is possible from any standard account of the forest.)

> I would also like to know if the same is possible for the local accounts
> for
> both 2000 and 2003 AD members and standalone servers?

The account used would need to have Users group membership on the
machines. Also, login rights for the type of access to be used for the
examination, network access from the monitoring machine(s), etc..

Roger



Posted by SVRSEC on September 10, 2007, 9:10 am
Please log in for more thread options
Let's assume that AD is tightened up a bit, I need to be able to see all
administrator accounts, and all information around them?

As far as the local accounts, our admins have added domain accounts to local
groups, so I need to be able to read the same information locally?

"Roger Abell [MVP]" wrote:

> >I need to know how, if possible, can you set up a user that can have read
> > access to AD to be able to browse all Administrator level accounts, but
> > not
> > be able to modify AD in any fashion? The reason for this is to be able to
> > have our security monitoring area be able to document and research any
> > Administrator level accounts anywhere in our AD.
> >
>
> If measures have not been taken to move your forest/domains away from
> the as-installed settings, then any account in the forest can do that (well,
> I guess it depends on what "able to browse all Administrator level accounts"
> intends to mean. If it means list out accounts in the groups, then that
> already
> is possible from any standard account of the forest.)
>
> > I would also like to know if the same is possible for the local accounts
> > for
> > both 2000 and 2003 AD members and standalone servers?
>
> The account used would need to have Users group membership on the
> machines. Also, login rights for the type of access to be used for the
> examination, network access from the monitoring machine(s), etc..
>
> Roger
>
>
>

Posted by Roger Abell [MVP] on September 11, 2007, 9:09 am
Please log in for more thread options
> Let's assume that AD is tightened up a bit, I need to be able to see all
> administrator accounts, and all information around them?
>
> As far as the local accounts, our admins have added domain accounts to
> local
> groups, so I need to be able to read the same information locally?
>

Have you tried?
AD objects carry default grants to Authenticated Users such that
what you seems to be indicating as needed ("see all administrator
accounts" - what do you mean by that __exactly__ ?) can happen.
For machine local accounts, I feel I previously provided answer.
Roger

> "Roger Abell [MVP]" wrote:
>
>> >I need to know how, if possible, can you set up a user that can have
>> >read
>> > access to AD to be able to browse all Administrator level accounts, but
>> > not
>> > be able to modify AD in any fashion? The reason for this is to be able
>> > to
>> > have our security monitoring area be able to document and research any
>> > Administrator level accounts anywhere in our AD.
>> >
>>
>> If measures have not been taken to move your forest/domains away from
>> the as-installed settings, then any account in the forest can do that
>> (well,
>> I guess it depends on what "able to browse all Administrator level
>> accounts"
>> intends to mean. If it means list out accounts in the groups, then that
>> already
>> is possible from any standard account of the forest.)
>>
>> > I would also like to know if the same is possible for the local
>> > accounts
>> > for
>> > both 2000 and 2003 AD members and standalone servers?
>>
>> The account used would need to have Users group membership on the
>> machines. Also, login rights for the type of access to be used for the
>> examination, network access from the monitoring machine(s), etc..
>>
>> Roger
>>
>>
>>



Similar ThreadsPosted
SP-1 to a Windows 2003 Server running SQL Server 2000 with out SP- July 5, 2005, 5:20 pm
windows 2000 server like home permistions on 2003 November 30, 2006, 1:00 pm
Make a filetype readonly March 13, 2007, 11:07 am
Open Ports on an Exchange 2000 on Server 2000 December 26, 2005, 5:27 pm
ASP.NET Performance Counters don't work monitoring several remote 2003 servers. February 1, 2007, 12:46 pm
creat a domain trust between Windows 2000 server, it show error message:"PRC server is unavailable" July 3, 2006, 3:59 pm
Server 2003 Std & RDC access September 6, 2006, 11:31 am
FTP Access On A Windows 2003 Server November 8, 2005, 4:26 am
cannot access web page on window 2003 server October 26, 2006, 9:51 pm
Server 2003 network directory access March 13, 2008, 4:56 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap