|
Guy recommends :
Find out which of your VMs are a waste of space and which VMs need more resources.
|
Security Settings - User RightsLocal Policies - User Rights AssignmentsThe first thing that you notice is just how many User Rights that Windows Server 2003 provides. Consequently, there is something for every aspect of security in this folder. A classic 'vanilla' installation of Active Directory will function adequately without you having to change any of these settings. The reason why you may never have to configure this section, is because many of these user rights are bestowed on people through membership of the appropriate group. For instance, place people who need to backup files in the backup operator's group. One company foolishly created a TechAdmin group and spent ages adding important rights, not realizing that there was already a built-in Administrators group which did the same job! Group Policy TopicsUser Configuration Windows Settings Audit Policy User Rights AssignmentsWhat then is the benefit of these settings? I would divide User Rights into three categories: 1) Rights for special accounts, example, the SQL Agent needs to Log on as a service. 2) Prevention of users getting into mischief, for example, 'Deny shutdown system' for a Terminal Server. 3) Specialist rights for one off situations, example allow roll-out team Add Workstations to domain. (But not make them full administrators) * Guy's Top Three User Rights Policies
‡ Rights for special accountsWhen you create service accounts you may wish to fine tune their capabilities. Such accounts are used by SQL and older versions of Exchange. The danger is that because service accounts are not allowed to change their password, they are a magnet for hackers to attack. More often than not, these service accounts have traditional names like SQLAdmin, so hackers guess their names, crack their password and breach the system. Your last line of defence is to give these accounts only specific rights, not full administrative control. Rights that fall into this special category are: Logon as a batch job, Logon as a service, Enable Computer Accounts to be trusted, Increase Scheduling Priority and possibly, Lock pages in memory.
Guy
Recommends: Permissions Analyzer - Free Active Directory Tool
| ||||
Custom Search
|
Guy Recommends:
|
|
Home Copyright © 1999-2012 Computer Performance LTD All rights reserved Please report a broken link, or an error. | |