Registered member login:
Register Now
Altirigos » Altiris Administrators » General » Altiris sys account as domain admin?

» Current Poll
Vista?
Staying on XP until Windows 7 - 72.14%
101 Votes
Already on Vista - 10.71%
15 Votes
Planning an upgrade to Vista soon - 10.00%
14 Votes
Other (please explain) - 7.14%
10 Votes
Total Votes: 140
You may not vote on this poll.
» Stats
Members: 6,831
Threads: 9,767
Posts: 47,811
Top Poster: Nick (4,800)
Welcome our newest member, jdh2000
» Online Users: 43
3 members and 40 guests
Kenneth, Randall LeDoux, rgone
Most users online at once 294, 06-30-2007 at 01:24 PM.
» January 2009
S M T W T F S
28293031 1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Reply
Old 10-15-2008, 03:49 PM   #1 (permalink)
 
Status: Junior Altiris Admin
Join Date: 01-10-2006
Location: Conroe TX
Posts: 26


Altiris sys account as domain admin?

Hi -

I have been asked to provide justification for why our Altiris systems are using a domain admin account. Honestly, even though I've worked with this stuff for 5 or 6 years now, at both jobs the system was configured as domain admin per the advice of the consultant.

I searched the forum and found some discussion on why it gets set up as domain admin, and the official stance in the doc that it does not need to be domain admin, but the user consensus seems to be that the hassles of it not being domain admin outweigh the risks of having the service account in domain admins.

I need to get a clear understanding, with examples if possible, of why.

My environment currently consists of 15k desktops, another 2k servers, and we have 5 DS, 5 NS, 2 SQL, and 20+ remote servers acting as local PXE.

We have taken steps to isolate processes in Altiris so that only the servers use domain admin rights, e.g. imaging got a special domain user account, pxe got a special domain user account, sql got an account for odbc, etc.

The domain account for the servers is what runs patch management, SWD, RAI and jobs from DS, etc. Only 2 admins know the account password.

If anybody could give me examples/pov on either scenario that would be much appreciated. thanks
naaron is offline   Reply With Quote
Old 10-15-2008, 03:58 PM   #2 (permalink)
 
Status: Junior Altiris Admin
Join Date: 09-24-2008
Location: USA
Posts: 5


I am very new to Altiris as well. The way we deployed Altiris was to use a separate account which we had to put in all the local administrator groups. This was a hassle.

Putting the account in domain admins would have been much easier, but I didn't want the account to be a domain admin if it didn't have to.
rdotson is offline   Reply With Quote
Old 10-16-2008, 12:22 PM   #3 (permalink)
 
depalo's Avatar
 
Status: Super Altiris Admin
Join Date: 03-29-2005
Location: TORONTO, ONTARIO
Age: 35
Posts: 148


the account does not need to be a domain admin.

domain admin is nice just in case u can't install an agent on a machine on the network.

otherwise, everything will work normally
__________________
Cosimo Depalo
Canadian Imperial Bank of Commerce (CIBC)
Toronto, Ontario
CANADA
Cosimo.Depalo@CIBC.ca
depalo is offline   Reply With Quote
Old 10-17-2008, 07:22 AM   #4 (permalink)
 
Status: Super Altiris Admin
Join Date: 11-09-2006
Location: London
Posts: 570


There is a principle of "least privilege" that says each account should have only the minimum privileges it needs to do the work.

You should have a separate account for each task:

1/ NS Service Account "Application identity" - admin access to NS servers only
2/ SQL Access account - required access to NS database only
3/ Client "push" account - workstation admins only
4/ Software install account (if required for badly written software packages) - workstation admins only
5/ Proxy access

and so on.

None of these accounts needs to be domain admins and shouldn't be. My last place wouldn't allow the Altiris Agent on Domain Controllers at all because they would then effectively give domain admin rights to Altiris Admins.
andykn is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Powered by vBadvanced CMPS v3.0 RC2

All times are GMT -4. The time now is 05:01 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
vB.Sponsors
Altirigos