third party log-agent on domaincontroller

Tangoball76 5 Reputation points
2024-01-31T07:16:15.7866667+00:00

Hello, we wanted to install in log-agent (wazuh / graylog / etc) on a domaincontroller (centrally managed) for IT-security-department If we do this, the administrator of management - tool (it-security-department) is also a domain-Administrator. Is it possible to do this only with read-rights? I am the Domain-Admin what is Microsoft best practice in this case?

Windows for business Windows Client for IT Pros Directory services Active Directory
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Thameur-BOURBITA 36,261 Reputation points Moderator
    2024-01-31T09:57:23.2466667+00:00

    Hi @Tangoball76

    You cannot install agent on a domain controller with only read permission. On member server you have to use a local admin account but on domain controller there is no local administrator

    If you want install the agent on domain controller , you have to use a admin account member of domain administrators group.

    In this case, you have to ask a admin alreday member of domain admins or administrators group to install the agent.

    Microsoft recommend to not install 3<sup>rd</sup> party applications on DCs and limit the use of Domain Admin privileges as mentioned in this Microsoft article : Updating best practices for Domain Controllers

    You should discuss with your security team if you can avoid to install this agent on all your domain controller in order to respect Microsoft best practise.


    Please don't forget to accept helpful answer

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.