Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

February 22, 2007 12:00 AM

Creating a Domain Global Group Called Member Computer Local Admins

Windows IT Pro
InstantDoc ID #94751
Rating: (6)

Q: A consultant for our company gave a computer Domain Admin rights in Active Directory (AD); he said it's necessary when pushing out Microsoft Systems Management Server (SMS) to clients. Is that true?

A: I don't recommend adding your SMS site server’s computer account to Domain Admins. The SMS site server doesn’t need Domain Admins authority; it just needs local administrator authority on computers in the domain in which it will be installing the SMS client. Making the SMS site server or any other server or application a member of Domain Admins is a quick way to give computers and their administrators access to each computer in the domain, but it also gives them access to AD. The principle of least privilege dictates that you never give people more authority than is necessary to do their jobs, and giving users Domain Admins authority can cause huge problems both through honest mistakes or malicious behavior.

The best way to handle this situation is to create a new domain global group called Member Computer Local Admins. Make computers that need administrator authority to other systems in the domain members of the Member Computer Local Admins group.

Then, create a Group Policy Object (GPO) with a Restricted Groups policy that makes Member Computer Local Admins a member of the Administrators local group. Apply that GPO to all the computers in the domain except for the domain controllers (DCs). You don’t want this policy to apply to your DCs because that would give the SMS site server administrator authority to AD.

To create and apply the GPO, open the Microsoft Management Console (MMC) Active Directory Users and Computers snap-in. Right-click the root of the domain, select Properties, then select the Group Policy tab. Click New to create a new GPO, and name it Restricted Group - Local Admins. Right-click the GPO, select Properties, then select the Security tab. Add a permission entry that denies DCs the Apply Group Policy permission, as shown in Figure 1. Adding this access control entry (ACE) will prevent DCs from applying this GPO, which will keep the Member Computer Local Admins group out of the domain’s Administrators local group. Click OK to close the Security and Properties dialog boxes.

Back at the Properties dialog box of the domain root, click Edit, which opens the MMC Group Policy Object Editor snap-in. Maneuver to Computer Configuration\Windows Settings\Security Settings\Restricted Groups as shown in Figure 2. Right-click Restricted Groups and select Add Group. Type in Administrators and click OK to close the Add Group dialog box. Windows will open a new properties dialog box for the policy. Under Members of this group, click Add, then Browse. Enter Member Computer Local Admins, and select Check Names. Click OK three times.

The Group Policy Object Editor should now show a policy that mandates that Member Computer Local Admins will be made a member of the Administrators local group when this GPO is applied. Because this GPO is linked to the root of the domain, every computer in the domain will apply this GPO except for DCs, because of the deny Apply Group Policy permission we assigned earlier.

The Group Policy Object Editor should now show a policy that mandates that Member Computer Local Admins will be made a member of the Administrators local group when this GPO is applied. Because this GPO is linked to the root of the domain, every computer in the domain will apply this GPO except for DCs, because of the deny Apply Group Policy permission we assigned earlier.

Related Content:

ARTICLE TOOLS

Comments
  • Anne
    4 years ago
    Apr 16, 2008

    malcomw, I'm sorry you've been having trouble with the site. If you could describe the problem more specifically, I'd be happy to try and help you. You can email me at agrubb@windowsitpro.com.
    Anne Grubb, Web strategic editor, Windows IT Pro

  • Malcolm
    4 years ago
    Apr 15, 2008

    This website is such a CON and this department will never visit the site again. Useless!!!!!

  • John
    5 years ago
    Feb 28, 2007

    ACCESS DENIED

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.