|
Verifying Delegated Access in Active Directory | |
|
|
Administrative access, even minimally possessed, is a very powerful and prized privilege and should always be delegated in a secure fashion.
Fundamental to delegating access in a secure fashion is the essential need to verify delegated authority so as to ensure that only authorized personnel (and no one else) can perform delegated administrative tasks.
In particular, it is imperative to ensure at all times that IT personnel who are delegated administrative authority for specific administrative tasks in specific administrative scopes can only –
- perform those tasks that were specifically delegated to them, and
- perform these tasks only within their administrative scopes.
This section helps IT administrators and managers understand the challenges in verifying delegated access in Active Directory and shows them how to accurately verify delegations in Active Directory.
|
|
|