Category Archives: Windows Server 2008

Administrator Role Separation in Windows Server 2008

Those of you already familiar with Windows Server 2008 will know that one of the key Active Directory-related improvements is the introduction of the Read-Only Domain Controller (RODC).  With the RODC comes the ability to separate administrative roles.  This removes the restriction of having to use a Domain Administrators account when carrying out administrative tasks… Read More: Administrator Role Separation in Windows Server 2008 »

My failed attempt to break aDDS using oWNER RIGHTS

Windows Server 2008 introduces a new security principal called OWNER RIGHTS.  It was introduced to fill a security and delegation loophole in previous versions of Windows whereby creators of objects potentially inherit more permissions than are intended.  For detailed information on how the new feature works in the context of AD, see Jorge’s blog entry… Read More: My failed attempt to break aDDS using oWNER RIGHTS »