DCSIMG
Enhancing Analysis 2005 Security - Revoking Domain Admin and Local Admin from Built in Admin role - BeI - Microsoft Business Intelligence

BeI - Microsoft Business Intelligence

By Yossi Elkayam (MCS Microsoft Israel) & Eran Sagi - (MS BI Regional Director)

Enhancing Analysis 2005 Security - Revoking Domain Admin and Local Admin from Built in Admin role

 

  • General
    By default Analysis 2005 sets the following accounts as server administrators:

Local Admin Group

Service Log-on account

 

To enhance analysis security, it's often requested to alter default policy by dropping domain and local admin account from server administrator role. This post describe the proper steps to perform in order to complete that task

 

 

  • Warning
    The following procedure would result dropping Local and domain administrator from the predefined Analysis Server Admin role. However it's not possible to block the local admin and/or domain admin from adding their logon to the server specific admin list. Once done, they would resume server administrator effective rights by the virtue of their own account rather than by prefixed role.

It's a good procedure to ensure strict corporate audit on that issue!

 

  • Procedure

 

1. Using the SQL Server management studio connect to the analysis server.

2. Right click the server instance name and choose security tab from the properties option

 

 

 

3. Add the genuine server administrator group (The assigned administrator group of the server)

4. Click Ok

 

5. Using the General tab click the "Show Advanced (All) Properties" checkbox.

6. Page through the properties window until reaching "Security\BuiltinAdminsAreServerAdmins"

7. Change the value to "false"

8. Verify that you have completed successfully steps 3-4 prior to that phase!!

9. Please verify that Analysis Server Service Log-On was set to an account other than local admin

    or domain admin. (do not change the "Security\ServiceAccountIsServerAdmin").

 

Enjoy :-)

 

Eran

פורסם: Mar 03 2008, 09:34 PM by Eran.Sagi | with 1 comment(s)
תגים:,

תוכן התגובה

www.ssas-info.com כתב/ה:

Link to this post was added to our site in the [Analysis Services Articles]/[Security] section:

www.ssas-info.com/.../848-enhancing-analysis-2005-security-revoking-domain-admin-and-local-admin-from-built-in-admin-role

# May 7, 2008 3:21 AM
שלח תגובה

(שדה חובה)  

(שדה חובה)  

(אופציונלי)

(שדה חובה) 

Please add 7 and 1 and type the answer here:


Enter the numbers above: