joeware - never stop exploring...

Information about joeware mixed with wild and crazy opinions…

The Forest, not the Domain is the security boundary in Windows Active Directory

by @ 9:38 pm on 7/17/2008.

I was recently pinged by a friend who had some consultants in at his company and the consultants I guess were going on about how the domain is the security boundary and it is perfectly safe/acceptable to have a bunch of child domains that are run by disparate groups of admins.

THIS IS INCORRECT!

It has ALWAYS been incorrect.

I expect until there is a really major redesign of AD such as PKI signed updates, etc it WILL REMAIN incorrect.

 

You cannot, I repeat, cannot protect the forest from any administrator in any domain in the forest. You can think you can, and a lot of people think they can, I see it all the time. But just because you as a technical person can’t think of a way to compromise a forest, doesn’t mean someone else can’t. Do not justify bad security decisions with your own technical shortcomings.

 

   joe

2 Responses to “The Forest, not the Domain is the security boundary in Windows Active Directory”

  1. Scotte Says:

    “Do not justify bad security decisions with your own technical shortcomings.”

    I might have to get that on a bumper sticker.

  2. Fred Woodbridge Says:

    Ha!

Leave a Reply

Please note: Comment moderation is currently enabled so there will be a delay between when you post your comment and when it shows up. Patience is a virtue; there’s no need to re-submit your comment.

Is this message spam? :)
This is Spam!
Of course this isn't Spam!!!

[powered by WordPress.]

27 queries. 0.382 seconds

Theme copyright © 2002–2008 Mike Little.