Re: Administrator Read Only by Banana
Banana
Thu Jul 15 22:35:39 CDT 2004
You could put him in a new group and assign readonly to all resources for
that group. That's a messy way though, admittedly.
I think really this comes down to a trust issue. Security
consultants/engineers shouldn't be allowed inside an organisation without
prior establishing that this is a trustworthy and ethical person. By nature
of their role they need to have a certain level of access, esp with MBSA
requiring remote registry access.
Ensure this person has established that trust and to make doubly sure enable
auditing (as well as checking audit logs) and make it clear that he is
accountable for any actions he may undertake, esp if he causes any damage.
HTH
"Toby Richards" <anonymous@discussions.microsoft.com> wrote in message
news:2db1801c46a7e$651eaff0$a501280a@phx.gbl...
Is there a way to give a user all the priviliges to look
at anything an Administrator can see, but prevent him from
making any changes. In my case, we're hiring a security
guy whose job will be to look for security flaws, but not
to change anything. Among other things, he'll need to run
MBSA on the domain, see group policies and event logs, and
audit file and folder permissions.