instance permissions in SMS 2003

From: Sai Wong [MSFT] (saiwong_at_online.microsoft.com)
Date: 10/19/04


Date: Tue, 19 Oct 2004 15:43:48 -0700

for the collection "All windows 2000 servers" make sure
you have also removed class level permissions.

Sai

This posting is provided "AS IS" with no warranties, and
confers no rights.

>-----Original Message-----
>Question - I would like to give a group limited
permissions to the
>Collections container. However, some of the collections
in there I
>would prefer no access to so I tried setting the
instance permissions
>for those objects (i.e. all windows 2000 servers) to No
Permissions
>but it did not do anything. How can I make this work?
>
>The alternative solution for what we are trying to
accomplish is to
>allow the group to create collections from single
instance software
>distribution but that appears to only be allowed at the
Collections
>level and not for specific subcollections. If there is
a way around
>this, that would work as well.
>
>Any help would be much appreciated!
>
>Frank
>.
>



Relevant Pages

  • Re: instance permissions in SMS 2003
    ... By deleting the class permissions within a collection, ... To make this analogus to NTFS permissions, ... > you have also removed class level permissions. ...
    (microsoft.public.sms.admin)
  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... Restricted Admins group to mitigate against what you propose Deji. ... also need to make sure the DAs in question cannot elevate their rights to EA, ... > By adding the Deny Write Permissions ACE, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... * This posting is provided "AS IS" with no warranties and confers no rights! ... > By adding the Deny Write Permissions ACE, ... > permission to modify the ACL on AdminSDHolder. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Why is Fedora not a Free GNU/Linux distributions?
    ... Taking away legitimate rights, yes, that would be immoral. ... specifically to be incompatible with the GPL, ... Software license) doesn't take away any right you had. ... There are other permissions that enable you to copy and distribute the ...
    (Fedora)
  • Re: Prevent changes to Administrator password
    ... Have you thought about delegating the exact permissions needed instead of using DA or restructing your forest? ... * This posting is provided "AS IS" with no warranties and confers no rights! ... > Restricted Admins group to mitigate against what you propose Deji. ...
    (microsoft.public.windows.server.active_directory)