The school of hard knocks teaches a lesson on managing Active Directory

Opinion
Jun 21, 20125 mins

What would you do if an administrator for an Active Directory sub-domain told you he had accidentally deleted his entire Organizational Unit? Temple University’s IT department learned a hard lesson about managing AD in a highly decentralized environment.

Temple University in Philadelphia is the 26th largest university in the country. Temple’s 17 schools and colleges provide higher learning and research capabilities for 45,000 students and 10,000 faculty members and staff. As is typical for any large educational institution, managing the IT infrastructure is a huge challenge. The various schools and departments are largely autonomous in choosing what devices and applications they install, but at some point, everyone and everything across the university has to share a topline directory system.

Temple’s IT environment is very mixed. The server infrastructure has an assortment of Microsoft, UNIX and Linux, and the tens of thousands of desktop devices are mostly Windows-based or Apple. The devices that are university-owned, as well as those owned by students living in the residence halls, are all part of a “permanent network” for directory services purposes. In all there are more than 92,000 accounts in the Active Directory infrastructure, including people who need access to Temple resources as well as non-person service accounts that perform programmatic functions.

GONE AMOK: 9 warning signs of bad IT architecture

The university has a central Information Technology group that has overall responsibility for setting up and supporting the campus-wide directory services. This group owns all the domain administrators and the top level architecture of AD as well as the underlying infrastructure. The group distributes rights to AD to non-centralized IT staffers who are employees of the different schools, colleges and business departments. These local staffers administer sub-domains.

One day last summer, the associate director of the IT department, Seth Shestack, got a call that no IT manager ever wants to take. A staff member who is a container administrator of one administrative unit accidently deleted his entire Active Directory Organizational Unit (OU). Oops!

It took the IT department staff three days to resurrect the OU.

For the university, this situation brought to light a serious issue with the way Active Directory is managed and rights are delegated. Natively within AD, when you give certain permissions, you automatically have to give other permissions. For example, if you are giving someone permission to manage a departmental OU, natively in the Microsoft software, you don’t have a way to restrict that admin’s ability to delete that unit or groups within that unit. A blanket level of permissions comes with that container administration privilege out of the box, and sometimes those permissions are just too broad.

Following the deletion debacle, Shestack’s IT group started looking for a third party management solution that would give them finer grained control and better oversight capabilities. They did a proof of concept test on products from two vendors and selected the StealthAUDIT Management Platform for Active Directory from STEALTHbits Technologies.

Shestack says the main reason his team selected this product was for the fine-grained control of the StealthINTERCEPT module. It gives the IT department the ability to restrict, block and prevent certain actions from occurring with AD. This is an important feature because of the type of incident the university experienced. Now the central IT department can tailor the privileges of an AD admin account specifically to the role that someone needs to take. There will be no more excess privileges that lead to another “oops!” moment.

The university was able to install, configure and fully implement StealthINTERCEPT in a relatively short period of time. Following the PoC last fall, they accomplished the whole implementation over the semester break this past winter. Everything was done by the time spring classes started in January. Now the IT department is able to lock down permissions for the local sub-domain administrators in a fine-grained manner.

During the spring semester, the university ran StealthAUDIT in monitoring mode in order to collect information about issues that they might want to automatically remediate without human intervention. This summer they are in the process of analyzing the instances and turning on the automatic remediation and will have it fully implemented by the start of fall classes.

Shestack says that STEALTHbits has helped the university gain control of its sprawling directory services system. Now the central administrators know exactly who is doing what with the lower level domains, and the likelihood of another mishap due to excessive privileges is practically eliminated.

Linda Musthaler is a principal analyst with Essential Solutions Corporation. You can write to her at LMusthaler@essential-iws.com.

______________________________________________________________

About Essential Solutions Corp:

Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.