COI Report – Part IV
Page
170 of
425 27.7.3 Creating and enforcing a GPO to block the access of domain administrator accounts to servers 538. On 7 July 2018, on Raymond’s instructions, the Active Directory Team created anew GPO (Group Policy Object) to block the access of domain administrator accounts to servers in their respective domains. The intention was that domain administrator accounts were not to be used to login to servers in their domain at all during that period. This, however, was distinct from removing the domain administrator
accounts entirely, which was not done.
539. The team implemented the GPO and specifically selected the option to enforce GPO, which is not something that is done usually.
This was done with the intention that the GPO should be implemented on all servers regardless of whether the server had been set to block policy inheritance. However, there was noway for the team to tell if the GPO was successfully implemented across all the servers, as there is no status report generated. The Active Directory Team simply sampled a few of the servers they managed in order to confirm that the GPO had been implemented.
They did not sample the Citrix servers.
27.7.4 Creating and implementing a GPO to prevent remote connections to domain controllers 540. At around am on 7 July 2018, Chee Choong created another GPO to prevent remote connections to domain controllers from domain clients using domain privilege accounts. Prior to this GPO, a domain administrator would be able to connect remotely to the domain controller from any machine.
Share with your friends: