Robert
Sun Jan 11 04:41:32 CST 2004
Philip Wang wrote:
> Hi guys, I would like to have some opinion on this.
> Recently we are doing some security audit and my boss
> said that we should surrender our Domain Administrator ID
> and keep the password in a safe.
>
> Other than using Domain Administrator to join PC /servers
> to domain, performing administrative tasks, etc, how can
> I convince my boss that it is essential for System
> Administrator like us to be responsible and keep the
> Domain Adminstrator account and password to ourselves?
Actually, I'm inclined to agree with your boss. You shouldn't be using the
domain administrator account day to day at all.
You should have "personal" admin accounts which you use for administrative
functions, that way you can track who made which changes. You should also
further have personal "user" accounts that you use for day to day "office
work" at your desks.
So you should be using personal admin accounts, and should only be logged
into them when you need to perform a task that requires administrative
rights.
--
--
Rob Moir
Microsoft MVP for servers & security
Website -
http://www.robertmoir.co.uk
Virtual PC 2004 FAQ -
http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html