Home > Ask the Windows Security Experts > Ask the Experts Archives, Inactive Questions & Answers > Need help with domain controller security policies
Ask The Windows Security Expert: Questions & Answers
EMAIL THIS

Need help with domain controller security policies

Roberta Bragg EXPERT RESPONSE FROM: Roberta Bragg

Pose a Question
Other Windows Security Categories
Meet all Windows Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 December 2003
I've just inherited a new Active Directory domain. Currently, there are two domain controllers called A and B. Domain controller A has no local security policy defined, no domain controller security policy defined and no domain security policy defined (all default). Domain controller B has some items defined in a local security policy, but no domain controller policy or domain security policy defined (all default). I have two questions about this:

1. Some users (non-administrators) exhibit the ability to add workstations to the domain while other users (also non-administrators) are denied that ability. Can I assume that is due to the user being authenticated by domain controllers with differing local security policies as outlined above (DC A does not allow, while DC B does allow)?

2. If the local security policy defined on DC B (specifically the "add workstations to domain" policy set to administrators and authenticated users) existed before the server was promoted to a DC, would that policy be inherited or assumed into the entire AD/Domain policy as a whole? And would this allow all authenticated users to add workstations or possibly creating a situation like in question 1 where it depends on where a users authentication takes place?


>
EXPERT RESPONSE
The whole idea of having a domain is to have a domain-wide security policy and to therefore have consistency within the domain on certain security issues, such as account policy (which includes password policy) and domain user rights. Then, where allowed and where approved as your organizations policy, security policy for various users and computers within the domain can be specified by creating GPO's on an organizational unit and creating a specific security policy there. I am confused when you say there is not a domain controller policy or domain policy on DC A, but some on B and that this is default. By default there is a GPO defined in both of these places, and by default, the domain controller policy for the domain is the same for all domain controllers in the domain. The domain policy for the domain is the same for all computers in the domain. If you are seeing different policies for each, I'd suspect a replication problem? Or worse?

Debugging security policy issues can be quite involved. When a server is promoted to a DC, if it is the first DC then it obtains its security policies from the template defined for domain controllers, which, of course, is an .inf file, a text file and could have been altered before the dc was promoted. If the DC is not the first DC, then it gets its policy from the existing DC that becomes its replication partner. Of course, as mentioned before, GPOs on OUs can mean different users will be able to do different things. Check the health of your Active Directory, and then determine just what GPO's are affecting the user accounts.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Ask the Experts Archives, Inactive
Recovering files from a Windows 2003 server
Converting user IDs to SIDs
Problems opening Group Policy snap-in
Problems accessing database files
Security configurations preventing programs from running
Adding domain groups using GPOs
Accessing the VPN after lock down
Resetting the default password policy
Conflicts among multiple GPOs
Methods for changing password policy settings

Authentication
Windows Server 2008 security aided by NAP and IPsec
Manage administrator rights in Windows Server 2003
Why don't I have proper Windows Server 2003 rights to open a GPO?
How can I prevent Internet access with Windows SBS?
Windows server security management: Security expert roundup
Windows server management with Remote Desktop
File management on a Windows Server 2003 NAS system
Windows Small Business Server 2003 access management
How to grant Microsoft Windows network permissions
Intrusion prevention for Windows network security
Authentication Research

Authentication
Correct improperly assigned user rights in Windows XP
How do I track file access in Windows folders?
Password security in Windows XP Professional
Cool things about security, nothing about Britney Spears
Sharing files and folders in Windows XP
Reduce resistance to creating strong computer passwords
Crack the admin password in Windows XP
Looking ahead to life without passwords
Learning center: Remote access authentication
Troubleshooting your Windows-based VPN
Authentication Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts