Follow us on Twitter Follow us on Facebook
Closed Thread
Results 1 to 4 of 4
What Sort of User Access Level Shall I Give?
  1. #1
    New Member
    This user has no status.
     


    Reputation
      

    Joined
         10th Nov 2010
    Online
         11th Nov 2010
    Posts
         6
    iTrader
         0

    As above, I have a few new starting IT guys, we want to start implementing access levels,
    We are running AD so any suggestions and experiance would be nice. I would add in unlocking users and reset passwords as basic level.
    But any other levels etc like stage 1, 2, 3, and then full admin.

    thanks in advance.
     Thread Starter
     ...to the topTop

  2. #2
    Donor VIP
    This user has no status.
     

    dmdougie's Avatar
    Reputation
      

    Joined
         28th Sep 2007
    Online
         12th Feb 2013
    Posts
         856
    iTrader
         0

    What version of server are you running? In 2008, there are plenty of builtin admin levels that have certain rights associated. For example, backup operator - given permissions to take backups only leading to more senior admins who are given access to everything bar editing any OU's within the domain. You can also make your own levels. A lot of it really depends on the scale and layout of your AD. Do you have multiple sites? Do you have multiple domains / trees?

    You should make up some domain level GPO's that monitor any changes made to the AD structure. Then, make up some Audit reports to filter out anyone who makes any changes at all - whether it be delete user, unlock account or even add/delete an OU.
    I Refuse To Have A Battle Of Wits With An Unarmed Person.

    If you tied buttered toast to the back of a cat
    and dropped it from a height, what would happen?
     ...to the topTop

  3. #3
    New Member
    This user has no status.
     


    Reputation
      

    Joined
         10th Nov 2010
    Online
         11th Nov 2010
    Posts
         6
    iTrader
         0

    its 2008 r2 64bit.
     Thread Starter
     ...to the topTop

  4. #4
    Donor VIP
    This user has no status.
     

    dmdougie's Avatar
    Reputation
      

    Joined
         28th Sep 2007
    Online
         12th Feb 2013
    Posts
         856
    iTrader
         0

    Do you know where the pre-set Admin accounts are?

    Server Manager > Roles > Domain name > builtin.

    To see all the permissions you'll have to go to View along the toolbar and enable advanced features. Double click on any of the pre-set groups to view their permissions. You can add the new IT admins to more than one group. So they can start off with only having access to resetting passwords, and then somewhere down the line you can add them to the Backup operators group, event log group etc etc.

    You can also makeup your own groups with whatever permissions, or you can juts alter existing ones.
    I Refuse To Have A Battle Of Wits With An Unarmed Person.

    If you tied buttered toast to the back of a cat
    and dropped it from a height, what would happen?
     ...to the topTop

 

 

Random Album Pictures

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts