Archived from groups: microsoft.public.win2000.security (
More info?)
Yes, I felt that...
Thanks for make me sure.
What about Group Policy, created in the root domain and linked to in the
child?
By default, child dom. admins can't edit, but can delete link.
Is it the same situation or it is possible to restrict this?
--
Gera
"Miha Pihler [MVP]" <mihap-news@atlantis.si> wrote in message
news:eLVBCVJ%23EHA.2180@TK2MSFTNGP12.phx.gbl...
> Hi,
>
> Yes, you are right; administrators will always be able to take ownership
of
> the folders.
>
> In this case, you might want to thing about EFS. If setup correctly it can
> protect information from administrators in child domain.
>
> I know this is easier said then done but domain administrators (even in
> child domain) should be trusted person -- or should not be a domain
> administrator.
>
> --
> Mike
> Microsoft MVP - Windows Security
>
> "Gera" <gera@ @lukrecija.lt> wrote in message
> news:%23vWC4LJ%23EHA.2580@TK2MSFTNGP15.phx.gbl...
> > And even the child domain's admin will be unable to take ownership?
> > Is it really so?
> >
> > I am concerned only in "protection from dom. admins"....
> >
> > --
> > Gera
> >
> >
> > "Miha Pihler [MVP]" <mihap-news@atlantis.si> wrote in message
> > news
![:o :o]()
%23VwnEJ%23EHA.3120@TK2MSFTNGP12.phx.gbl...
> >> Hi Gera,
> >>
> >> one option would be to run a script using
> >>
> >> Takeown
> >>
> >> tool that comes with Windows 2003. It can assign ownership to another
> >> user
> >> and therefore prevent user that created this folder to take ownership
in
> > the
> >> future.
> >>
> >> I hope this helps.
> >>
> >> --
> >> Mike
> >> Microsoft MVP - Windows Security
> >>
> >> "Gera" <Gera@discussions.microsoft.com> wrote in message
> >> news:21E1AE0C-47D6-4F38-BCDD-95ACE6932AAD@microsoft.com...
> >> > Situation: a forest consisting of a root domain and a child domain,
all
> >> > with
> >> > Win2003.
> >> > Is it possible to prevent admins from a child domain to do some tasks
> >> > or
> >> > replace ownership to their own in the child domain?
> >> >
> >> > Simple example: I create a folder on a child domain's DC and want to
> > leave
> >> > access to only Enterprise Admins from root domain. I set all the
perms,
> >> > take
> >> > ownership to Ent. admins., but child domain's admin still easily can
> >> > re-take
> >> > ownership and change ACL.
> >> >
> >> > Is it possible to solve?
> >> >
> >> > Thanks,
> >> > Gera
> >>
> >>
> >
> >
>
>