Is it every AD Domain Controller have to be DNS server?
And during migration phase (from NT to 2003), will the old WINS server (NT) be able to sync with new DNS server::
Are you sure about "not every domain controller has to be a dns server"?
I thought you have to have dns installed just before you can even install Active Directory.
You can bloke access to local drives which will help but it is not a total Safe. You can bloke the cd-rom, it might be wise to bloke autorun as well.
Depending on software applications, usb devices may still be accessible. To be totally safe on this you will need to purchase some software which will integrate into your AD groups. This would allow you to give access to some groups. Not sure of the software name but it can also control other ports. You might be able to disable USB ports on the local machines. Make sure the user can't login locally and they don't have access to computer manager.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.