Permission control across multiple domains

Hi There, here is my situation, My company is running NT4 and has over 10 different domains, all of them has 2-way trust relationship established with the IT Support Domain. For easier administration, we have created a Global Admin Account i...




Topic Options
#125625 - 05/07/03 08:27 PM Permission control across multiple domains
Mugen C Offline
journeyman

Registered: 09/15/00
Posts: 59
Hi There, here is my situation,

My company is running NT4 and has over 10 different domains, all of them has 2-way trust relationship established with the IT Support Domain.

For easier administration, we have created a Global Admin Account in the IT Support Domain, so that we can appliy patches/updates to other DCs and their servers with one master login name & password.

However, what I realize is, with this setup, everyone from the IT Team (including the part-time and co-ops) will now be able to access all the shared resources on other domains...which is not a good idea.

Now, my questions is...

Besides going through all the domains, servers and removing "everyone"
from each shared directories/resources, Is there an alternative/quicker way of accomplishing this task?...I am talking about over 200 servers and over thousands of shared resources... frown

Is there a way to write a script that we can restrict user access?

Or,

Was our apporach a big mistake (such as creating 2-way trust and Global Admin account?)

Thanks and look forward to hear from you soon! smile

regards,
Mugen C

Top
Advertisement
#125643 - 05/08/03 03:41 AM Re: Permission control across multiple domains
DS3Circuit Offline
old hand

Registered: 12/11/02
Posts: 739
Loc: Northeast PA
Quote:
Is there a way to write a script that we can restrict user access?


Check the resource kits from scriptable tools such as
http://www.ss64.com/nt/cacls.html
http://www.ss64.com/nt/xcalcs.html

In regards to your setup of multiple NT domains .... I personally would have recommended and encouraged a setup were there is an empty root domain where the rest of domains are children to the one empty ... with "enterprise" domain admins being heavily audited.

Why the two way trusts? Do children domains need to have access to the IT support domain? If so, were shortcut trusts not an option?

Quite honestly, I havent seen a scenario where
Quote:
one master login name & password
wasused throughout an entire forest for management as the one you have described .... perhaps its just me ...

Top
#126565 - 05/24/03 11:51 AM Re: Permission control across multiple domains
duhmez Offline
addict

Registered: 04/27/02
Posts: 583
Loc: Canada, West siiiiiiiiiide!
Remove the users that you dont want access from the domain admins group in the IT support domain, this will stop them from accessing the other servers directly. As for the shares if you set NTFS permission on your shares to allow only the groups you want, including domain admins, then they will be blocke form these shares as well, which will cure both problems in one swoop.


then audit and assign rights as needed.

Top


Forums
Windows Support Forums
Everything New Technology
Legacy OS
Hardware
Software
Games
Networking
Customization & Tweaking
Security

Linux Support Forums
Everything Linux
Linux Hardware
Linux Software
Linux Games
Linux Networking
Linux Customization & Tweaking
Linux Security

Apple Support Forums
Everything Apple
Recent Topics
Full guide: Review Some Useful Tools For iPod/iPho
by Lisaye007
3 seconds ago
How to Convert HD Video: TS, MTS, M2TS for Portabl
by ailsa123
3 minutes 38 seconds ago
Anything like HyperCam?
by Luckycharm8989
12/11/09 02:08 PM
Thank you for your help
by guaiguai
12/11/09 07:29 AM
What the problem is?
by guaiguai
12/11/09 05:09 AM
Who's Online
3 Registered (ailsa123, DosFreak, Lisaye007), 214 Guests and 32 Spiders online.
Key: Admin, Global Mod, Mod
Forum Stats
91318 Members
24 Forums
58774 Topics
189282 Posts

Max Online: 1079 @ 03/12/08 01:36 PM

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22