Deny password reset for helpdesk group
hi,
i have mix of windows 2008 r2 & windows 2012 r2 domain controllers in multiple site 2 exchange 2010 sites. for reason, don't want give helpdesk group password reset option. i denied option long , worked , cannot remember on ou or how denied. but now, for reason, group members able reset password. moreover, helpdesk users can add themselves domain admin users group well. how troubleshoot went wrong , restrict helpdesk resetting password , restricting helpdesk members adding domain admin group?
i not sure if domain admin group security, inheritance should enabled or not. now disabled.
kindly request fix issue.
kindly request fix issue.
unfortunately can not find have assigned permissions. step step fix create isolated ou has no inherited permissions domain, add administrators , domain admins permissions full control in ou , move sensitive accounts on there. remove help-desk users domain admins group , check if there explicit permissions on domain admin group itself. in case can lock desks down , prevent them touching domain admin group. cautious! not want lock down.
then start searching acl of desk group. there variety of tools that, 1 example:
once have list of not needed acls, remove them 1 one , check happens after. if went smoothly, move next acl.
this take time depending on environment. grab pen , paper because need keep track or lost. :)
mahdi tehrani | | www.mahditehrani.ir
make sure download free powershell scripts:
Windows Server > Directory Services
Comments
Post a Comment