Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Active Directory MSCs

Reply
Thread Tools Display Modes

Active Directory MSCs

 
 
Andy3691
Guest
Posts: n/a

 
      11-11-2009

I need to lock down access to the AD MSCs to just function on the DCs that
house AD. I don't want persons on the floor with the msc on their
desktops/laptops to have access. If someone whats/needs/thinks to do
something in AD they will need to enter the serverroom where I am and justify
what they intend to do. What is the best way for me to accomplish this?
 
Reply With Quote
 
 
 
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      11-11-2009
If you are talking about blocking the use of the mmc, you can't really do
that. Folks have read access to AD. I would be more concerned with
allowing people to enter your server room than to be using the mmc console.
Micro-managing an already secure system is only going to create a lot of
interuptions, if folks have the authority to make changes they shouldn't be
then take away their privileges.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Andy3691" <> wrote in message
news:848CBBF3-4F43-4B6E-8CB5-...
>I need to lock down access to the AD MSCs to just function on the DCs that
> house AD. I don't want persons on the floor with the msc on their
> desktops/laptops to have access. If someone whats/needs/thinks to do
> something in AD they will need to enter the serverroom where I am and
> justify
> what they intend to do. What is the best way for me to accomplish this?



 
Reply With Quote
 
Marcin
Guest
Posts: n/a

 
      11-11-2009
You can use Group Policy to prevent use of any/designated MMC snap-ins (User
Configuration\Administrative Templates\Windows Components\Microsoft
Management Console\Restricted Permitted snap-ins), just keep in mind that
this does not really bring you the desired results (as Paul has pointed
out)...

hth
Marcin

"Andy3691" <> wrote in message
news:848CBBF3-4F43-4B6E-8CB5-...
>I need to lock down access to the AD MSCs to just function on the DCs that
> house AD. I don't want persons on the floor with the msc on their
> desktops/laptops to have access. If someone whats/needs/thinks to do
> something in AD they will need to enter the serverroom where I am and
> justify
> what they intend to do. What is the best way for me to accomplish this?



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Active Directory with IPv6 Jorge Active Directory 4 11-12-2009 08:51 PM
Re: access time active directory Dusko Savatovic Windows Server 1 10-31-2009 05:43 AM
RE: access time active directory Steve Windows Server 0 10-30-2009 05:31 PM
Active Sync File Directory John Gregory ActiveSync 1 05-14-2008 08:48 PM
Windows Vista Bitlocker Active Directory Schema Ragnar Windows Vista Installation 6 02-01-2007 09:59 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59