A simple security question.

C

Chris Conley

Even though the Domain Admin is not on my allow list for a
specific resource he can still gain access correct? If I
implicitly deny access will he still be able to change the
security parms back to allow?
 
P

Phillip Windell

Yes. He just takes "ownership" of the object then sets the permission they
way he wants.
 
C

Chris Conley

-----Original Message-----
Yes. He just takes "ownership" of the object then sets the permission they
way he wants.

--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

Chris Conley said:
Even though the Domain Admin is not on my allow list for a
specific resource he can still gain access correct? If I
implicitly deny access will he still be able to change the
security parms back to allow?


.
I explicitly deny all control to the Domain Admin.
 
R

Richard G. Harper

It's a waste of time since you cannot deny a domain admin or local admin the
right to take ownership of an object.

It might help us determine how we can really help you (instead of simply
answering questions) if you gave us a clue on what you're trying to
accomplish here.

--
Richard G. Harper [MVP Win9x] (e-mail address removed)
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm
 
P

Phillip Windell

Just a guess,...maybe a user that wants to keep the IT Admin out of their
machine?

--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

Richard G. Harper said:
It's a waste of time since you cannot deny a domain admin or local admin the
right to take ownership of an object.

It might help us determine how we can really help you (instead of simply
answering questions) if you gave us a clue on what you're trying to
accomplish here.

--
Richard G. Harper [MVP Win9x] (e-mail address removed)
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm


Chris Conley said:
What if I explicitly deny the Domain Admin Full control to
all of C: drive?
 
R

Richard G. Harper

That was my guess too ... just wondered if he'd say it out loud.

I am a Domain Admin. I control the horizontal. I control the vertical.
If only I were an Exchange Admin, so I could read your Email. ;-)

--
Richard G. Harper [MVP Win9x] (e-mail address removed)
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm


Phillip Windell said:
Just a guess,...maybe a user that wants to keep the IT Admin out of their
machine?

--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

Richard G. Harper said:
It's a waste of time since you cannot deny a domain admin or local admin the
right to take ownership of an object.

It might help us determine how we can really help you (instead of simply
answering questions) if you gave us a clue on what you're trying to
accomplish here.

--
Richard G. Harper [MVP Win9x] (e-mail address removed)
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm


Chris Conley said:
What if I explicitly deny the Domain Admin Full control to
all of C: drive?
 
S

Steven L Umbach

They would not be able to access or logon to the computer. Of course they could
always change it back. You have to be an administrator on the local computer to do
that. I would not recommend doing such unless authorized. --- Steve
 
J

Jeff Cochran

Even though the Domain Admin is not on my allow list for a
specific resource he can still gain access correct? If I
implicitly deny access will he still be able to change the
security parms back to allow?

Simple analogy. You can take all the keys to the kingdom away from a
Domain Admin, but he has the power to keys. You can't stop him (and
will likely only make him mad...).

Jeff
 
P

Phillip Windell

Jeff Cochran said:
Simple analogy. You can take all the keys to the kingdom away from a
Domain Admin, but he has the power to keys. You can't stop him (and
will likely only make him mad...).

And that wouldn't be pretty. It might result in upgrading the PC to a
Manual Typewriter, a pencil sharpener and an Abacus.
 
P

Phillip Windell

Richard G. Harper said:
Pencil sharpener? You are generous to your minions, aren't you?

....can't have them sharpening it with a pocket knife,...they aren't allowed
to have weapons at work either... ;-)
 
R

Richard G. Harper

Ah - reasonable point.
I keep forgetting that not every workplace has scalpels. ;-)

--
Richard G. Harper [MVP Win9x] (e-mail address removed)
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top