<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Locking down AGPM fit for least privilege</title><link>http://blogs.technet.com/b/mkleef/archive/2008/11/18/locking-down-agpm-fit-for-least-privilege.aspx</link><description>A few customers have been emailing us. Essentially they want to be able to "lock down" AGPM as a central source of the GP truth and not allow it to have too much access...which is something I always advocate...if it doesnt need Domain Admin access then</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>AGPM Least Privilege Scenario</title><link>http://blogs.technet.com/b/mkleef/archive/2008/11/18/locking-down-agpm-fit-for-least-privilege.aspx#3169750</link><pubDate>Tue, 16 Dec 2008 18:58:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3169750</guid><dc:creator>Ask the Directory Services Team</dc:creator><description>&lt;p&gt;Mike here again. A customer recently asked how they should configure their Advanced Group Policy Management&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3169750" width="1" height="1"&gt;</description></item><item><title>Locking down AGPM for least privilege</title><link>http://blogs.technet.com/b/mkleef/archive/2008/11/18/locking-down-agpm-fit-for-least-privilege.aspx#3167610</link><pubDate>Fri, 12 Dec 2008 20:34:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3167610</guid><dc:creator>Group Policy Team Blog</dc:creator><description>&lt;p&gt;I actually wrote this post awhile ago on my blog and forgot to cross post this to the GP blog. Bad me...though&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3167610" width="1" height="1"&gt;</description></item><item><title>re: Locking down AGPM fit for least privilege</title><link>http://blogs.technet.com/b/mkleef/archive/2008/11/18/locking-down-agpm-fit-for-least-privilege.aspx#3161344</link><pubDate>Fri, 28 Nov 2008 23:20:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3161344</guid><dc:creator>Michael Kleef [AppSense]</dc:creator><description>&lt;p&gt;I have a caveat to this. These are the correct permissions to give it and everything works correctly though we have noticed a bug in deletion of a GPO that indicates in the progress UI the deletion failed when in fact it actually succeeds. We are investigating this bug. &lt;/p&gt;
&lt;p&gt;There are two workarounds:&lt;/p&gt;
&lt;p&gt;1. Revert back to using Domain Admins for the service account&lt;/p&gt;
&lt;p&gt;2. Ignore this error in this least privilege configuration&lt;/p&gt;
&lt;p&gt;I will report back if we find anything of further concern though we havent yet.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3161344" width="1" height="1"&gt;</description></item><item><title>re: Locking down AGPM fit for least privilege</title><link>http://blogs.technet.com/b/mkleef/archive/2008/11/18/locking-down-agpm-fit-for-least-privilege.aspx#3161195</link><pubDate>Fri, 28 Nov 2008 20:57:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3161195</guid><dc:creator>Nick Thompson</dc:creator><description>&lt;p&gt;Hurrah.. we've been wondering what rights to give our Service Account.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3161195" width="1" height="1"&gt;</description></item></channel></rss>