1,110 pts.
 Keeping Network Admin from accessing users’ home directories
We do not want our network administrator to have access to users home directories. How can we make this happen?

Software/Hardware used:
ASKED: November 9, 2010  3:54 PM
UPDATED: November 19, 2010  3:37 PM

Answer Wiki:
Depending on how you do permissions you can remove administrator from the access list either in active directory or NTFS permissions. Just log on as administrator and right click on whatever you wish to remove permissions from and share options and remove the administrator. Just be sure that someone has full control over the folder to make changes and perhaps make a back up account that has full access in case something happens to the owner of that account. The only thing is if he has full domain admin controls like mentioned he could potentially revert this change. So if it is a trust issue you probably look into replacing this guy or knocking him down on the permissions list to power user not administrator.
Last Wiki Answer Submitted:  November 10, 2010  2:07 pm  by  FrankTheTank   1,200 pts.
All Answer Wiki Contributors:  FrankTheTank   1,200 pts.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 

What is the domain functional level and the OS of the server on which the folders are kept?

 56,975 pts.

 

If your network admin is a member of the domain admin group that makes it difficult, but not impossible. He/she could always take ownership of the files, and then revert access back again.
Plus you could always audit the files and see when they were viewed or modified, if you have a reason the believe that the admin may be going where he/she is not supposed to be.
I agree with Technochic, you need to give some more info on this issue, and the OS’s being used.

 1,050 pts.

 

I think this is not possible without Administrator right. If general user have right to control home directories other than Administrator, hope it will possible. Or u have to use a 3rd party Sw for this purpose. But remember without knowledge don’t do that !

 22,035 pts.