Schema vs. Enterprise vs. Domain Admins

  • Section(s): Active Directory , Admin , Security
  • Published on Jun 20, 2007.
  • Last Modified on Jun 20, 2007.
  • Last Modified by Mitch Tulloch.
  • Rated 2.2 out of 5 based on 10 votes.
Domain admins can basically do anything, anywhere in the forest.

You have to choose who will be your domain admins very carefully, even in a multi-domain environment. That’s because there are exploits that can enable Domain Admins to make themselves into Enterprise Admins or even Schema Admins! And this works even if you are a Domain Admin in a child domain! What this means that if you need true separation of admin powers, you need to deploy multiple forests. That’s because the forest is the only real security boundary in Active Directory. Domains are not true security boundaries. And this is also reason that Microsoft has stopped promoting the idea of an empty forest root domain where only Enterprise Admins reside, since these exploits can enable a Domain Admin in a child domain to easily become an Enterprise Admin and own the forest.

***

Mitch Tulloch was lead author for the Windows Vista Resource Kit from Microsoft Press, which is THE book for IT pros who want to deploy, maintain and support Windows Vista in mid- and large-sized network environments. For more information see www.mtit.com.

About Mitch Tulloch

Mitch Tulloch was lead author for the Windows Vista Resource Kit from Microsoft Press, which is the book for IT pros who want to deploy, maintain and support Windows Vista in mid- and large-sized network environments. Mitch was also the author of Introducing Windows Server 2008 and technical project lead for the Microsoft Office Communications Server 2007 Resource Kit, both books also from Microsoft Press. For more information on these and other books by Mitch, see www.mtit.com .

Share this article


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Limited time offer!

SolarWinds screenshot

Subscribe to WindowsNetworking.com Newsletters today and get a free copy of the new SolarWinds Exchange Monitor!

Readers' Choice

Which is your preferred software-based Backup solution?