No GPO preventing the logon of administrators

HASSAN BIN NASIR DAR 306 Reputation points
2023-03-23T13:49:58.53+00:00

A way to collect an administrator credential is to take control of a workstation in the unsecure tiers and expect that an administrator will connect to it.

An attack such as credential theft or kerberos delegation is then performed.

To reduce the impact of such compromise, the best practice is to isolate components (such as admins, DC) in tiers.

Typically, a domain admin should not be allowed to connect to any workstation but login only to perform highly privileged operations.

How to prevent highly privileged admins (Tier 0) from accessing non-privileged resources?

How will admins access non-privileged resources?

Regards

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,077 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,817 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,496 Reputation points
    2023-03-23T14:43:05.1966667+00:00

    Hi @Chapter7-2723

    You can use user right assignement in GPO to deny access on T1 and T2 for T0 admins.

    Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment:

    User's image

    You should create a OU and GPO for each tiers after that ,

    On the OU T0 you link a GPO where you will deny access to T1 and T2 accounts on T0 assets

    On the OU T1 you link a GPO where you will deny access to T0 and T2 accounts on T1 assets

    On the OU T2 you link a GPO where you will deny access to T0 and T1 accounts on T2 assets

    Please don't forget to mark helpful answer as accepted

    0 comments No comments

  2. HASSAN BIN NASIR DAR 306 Reputation points
    2023-03-23T19:53:58.6833333+00:00

    Hi

    is there any other solution?

    Please answer me each question. Thanks

    0 comments No comments