Can I lock All Domain Admin Roles using Active Roles

Is it possible to completely lock out All domain admin roles using Active roles? We need to lock our AD so that no one can connect or access the AD other then via QAR. 

Parents
  • You shouldn't block native DA permissions but you definitely should control access to the DA group.  Have you seen the Just In Time Privilege Elevation integration with Safeguard?  This will allow admins to have accounts that can be DAs but aren't in the group until needed.  They would just check out their account, then the integration uses a combination of a virtual attribute and a dynamic group to make sure they get the right access.  When they're done they check their priv account back in and group membership is stripped, password is changed, and the account is disabled when not in use.    Here's a video link of the process.  

    https://youtu.be/3U4S7inJvs0?si=4MEYCy2Z9JyU_Zwe

Reply
  • You shouldn't block native DA permissions but you definitely should control access to the DA group.  Have you seen the Just In Time Privilege Elevation integration with Safeguard?  This will allow admins to have accounts that can be DAs but aren't in the group until needed.  They would just check out their account, then the integration uses a combination of a virtual attribute and a dynamic group to make sure they get the right access.  When they're done they check their priv account back in and group membership is stripped, password is changed, and the account is disabled when not in use.    Here's a video link of the process.  

    https://youtu.be/3U4S7inJvs0?si=4MEYCy2Z9JyU_Zwe

Children
No Data