ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Domain admin account as service account

    IT Discussion
    5
    17
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ
      last edited by

      Unfortunately, I had to use a domain admin account as a service account to get it to work properly. I would like to lock down this account as much as possible. I would like to block the account from logging into all but 4 servers if possible.

      1 Reply Last reply Reply Quote 0
      • StrongBadS
        StrongBad
        last edited by

        You want to lock down a domain admin account? What caused you to need to use a domain admin account?

        IRJI 1 Reply Last reply Reply Quote 1
        • thanksajdotcomT
          thanksajdotcom
          last edited by

          If the servers aren't DCs, can you just make local admin accounts to replace the domain admin account?

          IRJI 1 Reply Last reply Reply Quote 2
          • IRJI
            IRJ @thanksajdotcom
            last edited by

            @ajstringham said:

            If the servers aren't DCs, can you just make local admin accounts to replace the domain admin account?

            I wish I could

            StrongBadS 1 Reply Last reply Reply Quote 0
            • IRJI
              IRJ @StrongBad
              last edited by

              @StrongBad said:

              You want to lock down a domain admin account? What caused you to need to use a domain admin account?

              The application wont work otherwise. I have tried setting the minimum permissions required for months. I just cant get it to work right

              StrongBadS 1 Reply Last reply Reply Quote 0
              • StrongBadS
                StrongBad @IRJ
                last edited by

                @IRJ said:

                @ajstringham said:

                If the servers aren't DCs, can you just make local admin accounts to replace the domain admin account?

                I wish I could

                What technical issue is blocking you?

                1 Reply Last reply Reply Quote 0
                • IRJI
                  IRJ
                  last edited by IRJ

                  All I need are responses on how to lock down an account. Not how to get it to work without it being a DA account. Frankly it just wont work right otherwise. I have been trying to get it to work for months

                  thanksajdotcomT 1 Reply Last reply Reply Quote 0
                  • StrongBadS
                    StrongBad @IRJ
                    last edited by

                    @IRJ said:

                    @StrongBad said:

                    You want to lock down a domain admin account? What caused you to need to use a domain admin account?

                    The application wont work otherwise. I have tried setting the minimum permissions required for months. I just cant get it to work right

                    Can you provide any insight into the application or why the account isn't working?

                    1 Reply Last reply Reply Quote 0
                    • thanksajdotcomT
                      thanksajdotcom @IRJ
                      last edited by

                      @IRJ said:

                      All I need are responses on how to lock down an account. Not how to get it to work without it being a DA account. Frankly it just wont work right otherwise. I have been trying to get it to work for months

                      Just think about what you're asking. You want to lock down an account that, by its very design, is supposed to have master control. I don't know of any way to restrict a domain login to specific domain PCs. It's kind of counter-intuitive.

                      IRJI ? 2 Replies Last reply Reply Quote 0
                      • thanksajdotcomT
                        thanksajdotcom
                        last edited by

                        I'm doing research but I'm seeing the inverse of what you want. I'm finding results for how to restrict a PC to only one user, but not one user to only one PC.

                        1 Reply Last reply Reply Quote 0
                        • StrongBadS
                          StrongBad
                          last edited by StrongBad

                          Does this help?

                          We do something similar to this in our remote offices. First, create a group for the psuedo-admins in the domain. In AD, delegate control to the OU's they may need to manage (create/delete accounts, or maybe just reset passwords, or nothing at all).

                          Then use Group Policy to add your group to the local administrators group on the workstations and servers using Computer\Windows Settings\Security Settings\Restricted Groups. Do not deploy this policy to the Domain Controllers OU or the OUs containing your servers.

                          This obviously depends on having a AD configured in a manner to separate the client systems from the servers.

                          This is not my answer but is taken from ServerFault.

                          1 Reply Last reply Reply Quote 0
                          • IRJI
                            IRJ @thanksajdotcom
                            last edited by

                            @ajstringham said:

                            @IRJ said:

                            All I need are responses on how to lock down an account. Not how to get it to work without it being a DA account. Frankly it just wont work right otherwise. I have been trying to get it to work for months

                            Just think about what you're asking. You want to lock down an account that, by its very design, is supposed to have master control. I don't know of any way to restrict a domain login to specific domain PCs. It's kind of counter-intuitive.

                            I believe there is a way to restrict the account to just services if I remember correctly

                            1 Reply Last reply Reply Quote 0
                            • IRJI
                              IRJ
                              last edited by

                              I am going to put a pause on this question for the moment. I am going to force the vendor to give me specific access rights and I am not going to accept the domain admin account as the answer

                              1 Reply Last reply Reply Quote 3
                              • ?
                                A Former User @thanksajdotcom
                                last edited by A Former User

                                @ajstringham said:

                                I don't know of any way to restrict a domain login to specific domain PCs. It's kind of counter-intuitive.

                                Um.. Login Restrictions. It can actually be very useful!

                                login.png

                                thanksajdotcomT IRJI 2 Replies Last reply Reply Quote 1
                                • thanksajdotcomT
                                  thanksajdotcom @A Former User
                                  last edited by

                                  @thecreativeone91 said:

                                  @ajstringham said:

                                  I don't know of any way to restrict a domain login to specific domain PCs. It's kind of counter-intuitive.

                                  Um.. Login Restrictions. It can actually be very useful!

                                  login.png

                                  Ah, good to know! My bad!

                                  1 Reply Last reply Reply Quote 0
                                  • IRJI
                                    IRJ @A Former User
                                    last edited by

                                    @thecreativeone91 said:

                                    @ajstringham said:

                                    I don't know of any way to restrict a domain login to specific domain PCs. It's kind of counter-intuitive.

                                    Um.. Login Restrictions. It can actually be very useful!

                                    login.png

                                    That would be great if I could restrict the user from connecting to AD. In theory the user could just download the RSAT tools on one of the boxes they can log on to and remove their own restrictions.

                                    1 Reply Last reply Reply Quote 0
                                    • DashrenderD
                                      Dashrender
                                      last edited by

                                      For those same reasons you can't lock down a Domain Admin account.

                                      Solving the problem so you can use a non domain admin account is the only way to really lock it down.

                                      1 Reply Last reply Reply Quote 0
                                      • 1 / 1
                                      • First post
                                        Last post