Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Windows Small Business Server > Set privileges for new administrator

Reply
Thread Tools Display Modes

Set privileges for new administrator

 
 
Matt S
Guest
Posts: n/a

 
      06-30-2011
Hi,

I couldn't find an answer on the net, however apologies if this has
already been posted somewhere.

The situation is this, we are running SBS 2003 Premium (using SQL
server). For several years I have been the sole domain admin, however
now I can't allocate enough of my time to carry out all domain admin
tasks.

Therefore I would like to allow one of our users, who is IT literate
to help me manage the tasks of adding new users, setting up computers
for users, recovering lost passwords, unblocking locked accounts etc.

However if I create a new domain admin account for him to use for this
purpose, how do I restrict the following:

1. Gaining Access to folders of company directors - I could put a deny
right against the folders, but couldn't he just take ownership of the
folder?
2. Deleting users from the system?
3. Accessing an sql server table containing employee salaries? - again
I can put a deny right but couldn't he override this?

The above may sound paranoid, as I do trust the employee, however I do
need to ensure I undertake due diligence with company IT security.

Any help would be appreciated.
 
Reply With Quote
 
 
 
 
Steve Foster
Guest
Posts: n/a

 
      07-03-2011
Matt S wrote:

> Hi,
>
> I couldn't find an answer on the net, however apologies if this has
> already been posted somewhere.
>
> The situation is this, we are running SBS 2003 Premium (using SQL
> server). For several years I have been the sole domain admin, however
> now I can't allocate enough of my time to carry out all domain admin
> tasks.
>
> Therefore I would like to allow one of our users, who is IT literate
> to help me manage the tasks of adding new users, setting up computers
> for users, recovering lost passwords, unblocking locked accounts etc.
>
> However if I create a new domain admin account for him to use for this
> purpose, how do I restrict the following:
>
> 1. Gaining Access to folders of company directors - I could put a deny
> right against the folders, but couldn't he just take ownership of the
> folder?
> 2. Deleting users from the system?
> 3. Accessing an sql server table containing employee salaries? - again
> I can put a deny right but couldn't he override this?
>
> The above may sound paranoid, as I do trust the employee, however I do
> need to ensure I undertake due diligence with company IT security.
>
> Any help would be appreciated.


1. You must have complete faith in anyone who is granted Domain Admin
privileges.

2. If you want to offer a subset of this, create a group accordingly,
and grant the relevant privileges to the group. ISTR that SBS2003 had a
group for this purpose, but I don't have one handy to look at right now.

--
Steve Foster
For SSL Certificates, Domains, etc, visit.:
https://netshop.virtual-isp.net
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Help: What is the administrator password? What if I've never set i john ha Windows Vista Security 14 05-13-2010 07:44 AM
ANS: "What's the deal with UAC (Windows Needs Your Permission screens)" and "...But I thought I was an administrator" Jimmy Brush Windows Vista Administration 199 12-31-2009 07:58 AM
Administrator Privileges - Catch 22 - AARGH! Sidebar Seeker Windows Vista Administration 2 01-19-2008 08:52 AM
Windows Vista Administrator account off but on? cheesegrater Windows Vista Administration 16 08-31-2007 05:23 PM
Administrator w/out Privileges Ed P Windows Vista Administration 1 08-03-2007 06:22 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59