ISLAB Logs
So that accounts with different risk get different policies and different handling: elevated accounts, ordinary users and non-human service accounts.
Privileged: accounts with elevated rights, for example department heads or administrators. They deserve stricter policies (strong...
Q A freshly created domain user cannot open a Remote Desktop session to a domain-joined PC ("not autho...
Remote Desktop logon is only allowed for members of the PC's local Administrators or Remote Desktop Users group, and the new user is in neither. The fix is a GPO that puts the right domain group into that local group on every PC.
Every Windows machine has its own local groups, se...
Q How do share permissions and NTFS permissions interact, and why is the share often set to Everyone:...
Access over the network must pass both layers, and the more restrictive one wins. So a common practice is to keep the share wide open and do all the fine-grained control in NTFS.
* Over the network both layers apply; locally only NTFS. *
A folder shared over the network (SMB) ha...
Q What are the two AD group types, and what is each one for?
Security groups are used to grant permissions; distribution groups are only email distribution lists and cannot be used in access control.
Security group: has a security identifier (SID) that goes into the member's logon token, so it can be put on access lists (file shares, fold...
Q What does the Restricted Groups policy do, and what is Administrators in this context?
Restricted Groups lets a GPO define the exact membership of a local group on every targeted computer; Administrators here is the built-in local group of each machine, not a domain group.
* On refresh the local group is set to exactly the GPO's list. *
Each Windows computer has a...
Q On a new folder like C:\Daten, the local Users group has "Special" permissions. What are they, and w...
Users inherits from the C:\ root the rights to create folders and create files inside the folder, on top of read and execute. On a data share, that would let every user write where they shouldn't.
The default access list on the system drive gives Users:
Read & execute (this fold...
Q What are the three AD group scopes, and how do they differ?
Global groups collect users of their own domain and can be used anywhere in the forest; domain local groups can contain members from anywhere but grant rights only in their own domain; universal groups do both and are best avoided.
Scope
Can contain
Can be granted rights in...
Q What is the effect of adding the local account labadmin to Administrators via Restricted Groups?
labadmin stays (or becomes) a local administrator on every computer the GPO applies to, and survives the authoritative membership reset.
Because Restricted Groups replaces the group membership on each refresh, a local admin account that is not in the list would be thrown out. Lis...
Q What is the difference between the groups Users and Domain Users?
Users is a built-in local group that exists on every machine; Domain Users is a global group in AD that contains every user account of the domain.
Domain Users lives in Active Directory. Every user account created in the domain is automatically a member. It is the same group on...
Q What is Active Directory, and which jobs does it do in identity and access management?
Active Directory (AD) is Microsoft's directory service: one central database of a Windows domain's users, computers, groups and other objects, used to authenticate them and to decide what they may access.
Without a directory every server keeps its own user list, and giving one pe...