P
P
pkruglov2013-01-30 09:53:14
Windows
pkruglov, 2013-01-30 09:53:14

How to implement restricted admin in Windows?

It is necessary that the administrator could not perform some actions, for example, clean the system logs. Otherwise, it is necessary that his rights be complete. Is it possible to somehow implement this on Windows 2008?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
@
@ntkt, 2013-01-30
_

In general, this is impossible. The domain administrator can regain any rights.
The way out is to revise the security policy, to give administrative powers to the minimum number of people.
Logs are forwarded to dedicated servers, access to which is regulated separately, etc.
Since 2008 there is a dedicated group for "Chukchi log readers" - "Event Log Readers".

T
t_q_l, 2013-02-01
@t_q_l

It is necessary that the administrator could not perform some actions, for example, clean the system logs. Otherwise, it is necessary that his rights be complete. Is it possible to somehow implement this on Windows 2008?

If the problem is only to save the logs, then the logs can be written to a remote server.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question